CVE-2025-60574
HIGHtQuadra CMS 4.2.1117 - Local File Inclusion via Styles Path
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-60574. PoCs published by jacopoaugelli.
AI-analyzed exploit summary The PoC demonstrates a Local File Inclusion (LFI) vulnerability in tQuadra CMS 4.2.1117 via the '/styles/' path, allowing arbitrary file retrieval. The provided curl command exploits this by fetching '/etc/passwd' from the target system.
Description
A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.
Exploits (1)
The PoC demonstrates a Local File Inclusion (LFI) vulnerability in tQuadra CMS 4.2.1117 via the '/styles/' path, allowing arbitrary file retrieval. The provided curl command exploits this by fetching '/etc/passwd' from the target system.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N