The id of the user is passed through the querystring in this page. But the id was not properly escaped to be included as a querystring parameter leading to weird issues like.