Crapazon's post-payment redirect takes a URL from the query string and doesn't validate it. Send a customer anywhere after checkout.