Unrestricted File Upload Vulnerability in yii2-starter-kit by yii-starter-kit
CVE-2026-103474

8.7HIGH

Key Information:

Vendor
CVE Published:
30 September 2026

What is CVE-2026-103474?

The yii2-starter-kit, up to version 4.2.0, is susceptible to a serious vulnerability that allows authenticated users, specifically those with manager privileges, to upload PHP files to the backend storage. This flaw arises from inadequate validation of file types during file upload actions. As a result, attackers can exploit this vulnerability by uploading malicious PHP scripts to a public directory, potentially executing arbitrary code on the server. It's crucial for users of the yii2-starter-kit to implement safeguards to mitigate risks associated with this issue.

Affected Version(s)

yii2-starter-kit 0 <= 4.2.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vikash Gupta
.