CVE-2025-60574

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.
References
Link Resource
https://github.com/jacopoaugelli/CVE-2025-60574 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:webair:tquadra_cms:4.2.1117:*:*:*:*:*:*:*

History

11 Dec 2025, 23:39

Type Values Removed Values Added
First Time Webair tquadra Cms
Webair
CPE cpe:2.3:a:webair:tquadra_cms:4.2.1117:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad de inclusión local de ficheros (LFI) ha sido identificada en tQuadra CMS 4.2.1117. El problema existe en la ruta "/styles/", que no logra sanear correctamente la entrada proporcionada por el usuario. Un atacante puede explotar esto enviando una solicitud GET manipulada para recuperar ficheros arbitrarios del sistema subyacente.
References () https://github.com/jacopoaugelli/CVE-2025-60574 - () https://github.com/jacopoaugelli/CVE-2025-60574 - Exploit, Third Party Advisory

10 Nov 2025, 15:15

Type Values Removed Values Added
CWE CWE-98
CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

07 Nov 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-07 22:15

Updated : 2025-12-11 23:39


NVD link : CVE-2025-60574

Mitre link : CVE-2025-60574

CVE.ORG link : CVE-2025-60574


JSON object : View

Products Affected

webair

  • tquadra_cms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')