Description
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
Published: 2026-09-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because yii2-starter-kit does not validate the type of files uploaded through its backend storage endpoints, allowing authenticated managers to upload PHP files. If an attacker uploads a PHP script to the web‑accessible storage directory and then requests it, the script executes on the server, giving the attacker arbitrary code execution and potentially full control of the system.

Affected Systems

Instances of yii2-starter-kit running version 4.2.0 or older are susceptible. The flaw exists in the backend file upload action used by users with manager privileges.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. Exploitation requires only a manager role and an authenticated session; once a malicious PHP file is stored, the attacker can invoke it to run arbitrary code. The EPSS score is not available and the issue is not listed in CISA KEV, so the exact likelihood of exploitation is unknown, but the potential impact is severe.

Generated by OpenCVE AI on September 30, 2026 at 19:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade yii2-starter-kit to the latest release that includes a file‑type validation fix for the upload endpoint.
  • If an upgrade cannot be performed immediately, relocate the upload directory outside the web root or configure the web server to deny execution of scripts in that directory.
  • Implement strict file‑type validation that permits only allowed image formats and rejects all other file types before storing the file.

Generated by OpenCVE AI on September 30, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Yii2-starter-kit
Yii2-starter-kit yii2-starter-kit
Vendors & Products Yii2-starter-kit
Yii2-starter-kit yii2-starter-kit

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
Title yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Yii2-starter-kit Yii2-starter-kit
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T17:50:39.433Z

Reserved: 2026-09-30T16:03:00.349Z

Link: CVE-2026-103474

cve-icon Vulnrichment

Updated: 2026-09-30T17:50:29.092Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:17.647

Modified: 2026-09-30T19:08:43.927

Link: CVE-2026-103474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:38:47Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type