Description
When an nginx web server implements an HTTP redirect by using the $uri or $document_uri variables within the redirection target location, the resulting configuration may be vulnerable to header injection.
Remediation
Implement the HTTP redirect with $request_uri instead of $uri or $document_uri.
References
Related Vulnerabilities
WordPress Plugin Persian Woocommerce SMS Cross-Site Scripting (3.3.2)
WordPress Plugin Code Embed 'suffix' Parameter Cross-Site Scripting (2.0.1)
WordPress Plugin eHive Object Details Cross-Site Scripting (2.1.6)
WordPress Plugin Calculated Fields Form Cross-Site Scripting (1.0.353)
WordPress Plugin 10Web Map Builder for Google Maps Cross-Site Scripting (1.0.69)