Open redirects lend trusted domains to phishing

A redirect that will send users anywhere lets an attacker send a link that genuinely starts at your domain.

The victim checks the address, sees your name, clicks, and arrives somewhere else. Nothing on your site was compromised; you have simply lent your credibility. It is usually dismissed as low severity and is a significant multiplier for phishing against your own customers.

More on Web application security