The application is vulnerable to reflected cross site scripting attacks. Attackers can insert JavaScript into requests which are then reflected by the server in the response and executed by the browser.  If an attacker tricks a user into clicking on a malicious link, the page sent in the response will be modified to include injected JavaScript that will execute under the context of the user.

