NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter.