mode: xss · SPA_ORIGIN: https://ox0.in · host: auth-poc.ox0.in
If you can read this page, the SPA assigned the attacker-controlled Location header to window.location.href.