Stored XSS Vulnerability in @apostrophecms/seo via Unsanitized Google Analytics / GTM ID
A stored XSS vulnerability exists in the @apostrophecms/seo package, allowing an editor-level user to inject malicious JavaScript into the site, affecting all visitors. The vulnerability is caused by unsanitized Google Analytics and Google Tag Manager IDs being injected into script tags.