Description
When an nginx web server implements an HTTP redirect by using the $uri or $document_uri variables within the redirection target location, the resulting configuration may be vulnerable to header injection.
Remediation
Implement the HTTP redirect with $request_uri instead of $uri or $document_uri.
References
Related Vulnerabilities
WordPress Plugin LiteSpeed Cache Cross-Site Scripting (3.6)
WordPress Plugin FormBuilder Cross-Site Scripting (0.90)
WordPress Plugin Product Addons & Fields for WooCommerce Same Origin Method Execution (SOME) (14.0)
WordPress Plugin YOP Poll Cross-Site Scripting (6.0.2)
WordPress Plugin Gmedia Photo Gallery Cross-Site Scripting (0.9.3)