Yes still. OAuth return URL. Patched with an allow-list. This is on-topic because people still call it 'just phishing'.
It is an authorization bug. Write it that way.
Refs: CVE Program
Lab / educational. Public binaries and patched classes only. Isolated VM.