A Local File Inclusion (LFI) vulnerability has been...
Unreviewed
Published
Nov 8, 2025
to the GitHub Advisory Database
•
Updated Nov 8, 2025
Description
Published by the National Vulnerability Database
Nov 7, 2025
Published to the GitHub Advisory Database
Nov 8, 2025
Last updated
Nov 8, 2025
A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.
References