# Real Post Slider Lite 存储型XSS漏洞
## 概述
Real Post Slider Lite 插件存在存储型跨站脚本漏洞(Stored XSS),影响版本至 2.4(含)。
## 影响版本
所有版本 ≤ 2.4。
## 细节
漏洞源于插件设置中对输入数据缺少充分的输入过滤与输出转义。经身份认证且具备管理员权限的攻击者可利用此漏洞在页面中注入恶意脚本。
## 影响
恶意脚本将在用户访问受影响页面时执行。该问题仅影响以下情况:
- WordPress 多站点(Multisite)安装环境,或
- `unfiltered_html` 功能被禁用的安装环境。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: ERROR: The request could not be satisfied -- 🔗来源链接
标签:
神龙速读:
### 关键信息
- **状态码**: 403 ERROR
- **请求问题**: The request could not be satisfied.
- **原因**: Request blocked. We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error.
- **建议措施**:
- Try again later.
- Contact the app or website owner.
- **CloudFront文档**: If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation.
- **生成来源**: Generated by cloudfront (CloudFront)
- **请求ID**: gax6vr33J4Cw8gxrs3FGk2Gb1ZYb7qP7_x2Fc_xl6kgba5TSxwa1Q==
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.