Security labReflected XSSThe search page reflects the ?q= parameter directly into the HTML response without sanitization.