User-controlled search input is reflected without sanitization, allowing arbitrary JavaScript execution.