Redirecting to a URL taken from params lets attackers send users to arbitrary sites.
Redirect only to validated internal paths or set allow_other_host to false.