Edmodo Host Header Injection / Redirection PoC Video.
Here the Server was redirecting to a new URL by location: parameter, without any X-Forwarded-Host, which allows any attacker to inject a new X-Forwarded-Host:domain.name to redirect to the new host.