AntiPattern
Client-Controlled Redirects
client-controlled-redirect-spoofing
Client-controlled inputs (URLs, query strings, headers, and path segments) can be spliced into server logic or payment flows, letting attackers redirect or spoof outcomes so the system cannot reliably verify what actually happened.