CVE-2025-60574
HIGHtQuadra CMS 4.2.1117 - LFI
Title source: llmDescription
A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0009
EPSS Percentile
25.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
CWE-98
Status
published
Products (1)
webair/tquadra_cms
4.2.1117
Published
Nov 07, 2025
Tracked Since
Feb 18, 2026