Unrestricted File Upload Vulnerability in yii2-starter-kit by yii-starter-kit
CVE-2026-103474
8.7HIGH
What is CVE-2026-103474?
The yii2-starter-kit, up to version 4.2.0, is susceptible to a serious vulnerability that allows authenticated users, specifically those with manager privileges, to upload PHP files to the backend storage. This flaw arises from inadequate validation of file types during file upload actions. As a result, attackers can exploit this vulnerability by uploading malicious PHP scripts to a public directory, potentially executing arbitrary code on the server. It's crucial for users of the yii2-starter-kit to implement safeguards to mitigate risks associated with this issue.
Affected Version(s)
yii2-starter-kit 0 <= 4.2.0
