The vulnerability exists due to improper input sanitization parameters applied to the global search engine query fields. This allows an authenticated attacker to inject malicious strings, executing arbitrary cross-site scripting (XSS) actions inside other users' sessions.