Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter. References: https://support.zabbix.com/browse/ZBX-10272 https://support.zabbix.com/browse/ZBX-13133
This is an old vulnerability that was fixed quite a while ago.