A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/jacopoaugelli/CVE-2025-60574 |
|
History
Mon, 10 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 CWE-98 |
|
| Metrics |
cvssV3_1
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tquadra
Tquadra tquadra Cms |
|
| Vendors & Products |
Tquadra
Tquadra tquadra Cms |
Fri, 07 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-07T00:00:00.000Z
Updated: 2025-11-10T15:04:25.257Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60574
Updated: 2025-11-10T15:03:29.265Z
Status : Awaiting Analysis
Published: 2025-11-07T22:15:39.210
Modified: 2025-11-12T16:20:22.257
Link: CVE-2025-60574
No data.