CVE-2026-103474
yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
| CWE | CWE-434 |
| Vendor | yii2-starter-kit |
| Product | yii2-starter-kit |
| Published | Sep 30, 2026 |
| Last Updated | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for yii2-starter-kit yii2-starter-kit
Be the first to know when new high vulnerabilities affecting yii2-starter-kit yii2-starter-kit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
yii2-starter-kit / yii2-starter-kit
0 โค 4.2.0
References
github.com: https://github.com/yii-starter-kit/yii2-starter-kit/issues/797 github.com: https://github.com/yii-starter-kit/yii2-starter-kit github.com: https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/backend/modules/file/controllers/StorageController.php#L36 vulncheck.com: https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unrestricted-file-upload-rce
Credits
Vikash Gupta