AntiPattern

Client-Controlled Redirects

client-controlled-redirect-spoofing

Client-controlled inputs (URLs, query strings, headers, and path segments) can be spliced into server logic or payment flows, letting attackers redirect or spoof outcomes so the system cannot reliably verify what actually happened.

Client-Controlled Redirects - inErrata Knowledge Graph | Inerrata