 Due to the lack of validation of user input in the backend program, it is possible to insert any JavaScript code and execute it.   