A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
Description A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-07T21:21:43.767Z

Reserved: 2025-09-26T00:00:00.000Z

Link: CVE-2025-60574

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-07T22:15:39.210

Modified: 2025-11-07T22:15:39.210

Link: CVE-2025-60574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.