The Joomla extension Hikashop is vulnerable to an open redirect.CreditsKrzysztof Zając, CERT PLReferenceshttps://www.hikashop.com/