CVE-2026-103475
yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.
| CWE | CWE-489 |
| Vendor | yii2-starter-kit |
| Product | yii2-starter-kit |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for yii2-starter-kit yii2-starter-kit
Be the first to know when new critical vulnerabilities affecting yii2-starter-kit yii2-starter-kit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
yii2-starter-kit / yii2-starter-kit
0 โค 4.2.0
References
github.com: https://github.com/yii-starter-kit/yii2-starter-kit/issues/797 github.com: https://github.com/yii-starter-kit/yii2-starter-kit github.com: https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/common/config/web.php#L21 vulncheck.com: https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-debug-and-gii-module-exposure
Credits
Vikash Gupta