High severity7.5NVD Advisory· Published Nov 7, 2025· Updated Jun 17, 2026
CVE-2025-60574
CVE-2025-60574
Description
A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:webair:tquadra_cms:4.2.1117:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: =4.2.1117
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.