What's sad is that not even wrong security was in place here. They didn't even try. There was NO XSS prevention.
<script>javascript</script> is the first payload you try when looking for the stupidest XSS you can find....
<script>javascript</script> is the first payload you try when looking for the stupidest XSS you can find....
I'm not saying that's what happened here, and depending on the language and platform you're using, xss can be a difficult problem to solve. But it does seem to be a common trait to disregard security until you have to apologize for it.