CVE-2026-103474
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| yii2-starter-kit | yii2-starter-kit | 0 <= 4.2.0 | affected |
Weaknesses
- CWE-434: Unrestricted Upload of File with Dangerous Type
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/yii-starter-kit/yii2-starter-kit/issues/797
- https://github.com/yii-starter-kit/yii2-starter-kit
- https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/backend/modules/file/controllers/StorageController.php#L36
- https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unrestricted-file-upload-rce
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.