Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103474 | 1 Yii2-starter-kit | 1 Yii2-starter-kit | 2026-10-01 | 8.8 High |
| yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server. | ||||
| CVE-2026-103475 | 1 Yii2-starter-kit | 1 Yii2-starter-kit | 2026-10-01 | 9.1 Critical |
| yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory. | ||||
| CVE-2026-103476 | 1 Yii2-starter-kit | 1 Yii2-starter-kit | 2026-10-01 | 5.3 Medium |
| yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks. | ||||
Page 1 of 1.