Description
When an nginx web server implements an HTTP redirect by using the $uri or $document_uri variables within the redirection target location, the resulting configuration may be vulnerable to header injection.
Remediation
Implement the HTTP redirect with $request_uri instead of $uri or $document_uri.
References
Related Vulnerabilities
WordPress Plugin Calculated Fields Form Cross-Site Scripting (1.0.81)
WordPress Plugin Publish to Schedule Cross-Site Scripting (4.5.4)
WordPress Plugin Realia Cross-Site Scripting (0.9.1)
WordPress Plugin WP-PostRatings Cross-Site Scripting (1.50)
WordPress Plugin BSK PDF Manager Multiple Cross-Site Scripting Vulnerabilities (1.3)