How would a malicious user embed the script?
It turns out that it’s fairly easy for a malicious user to create a hyperlink that takes a user to a web page of the malicious user’s choice and fills in one or more fields with arbitrary input, potentially including script. The real challenge in this attack lies in social engineering – how to entice the user into clicking on the link, how to set up the attack so that when the user clicks on the link, he goes someplace he expected to but doesn’t notice that one field has been filled in, etc.