Executive Summary

A stored XSS vulnerability exists in the `@apostrophecms/seo` package, allowing an editor-level user to inject malicious JavaScript into the site, affecting all visitors. The vulnerability is caused by unsanitized Google Analytics and Google Tag Manager IDs being injected into script tags.

Technical Analysis

The `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `