Impact
The vulnerability arises because yii2-starter-kit does not validate the type of files uploaded through its backend storage endpoints, allowing authenticated managers to upload PHP files. If an attacker uploads a PHP script to the web‑accessible storage directory and then requests it, the script executes on the server, giving the attacker arbitrary code execution and potentially full control of the system.
Affected Systems
Instances of yii2-starter-kit running version 4.2.0 or older are susceptible. The flaw exists in the backend file upload action used by users with manager privileges.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. Exploitation requires only a manager role and an authenticated session; once a malicious PHP file is stored, the attacker can invoke it to run arbitrary code. The EPSS score is not available and the issue is not listed in CISA KEV, so the exact likelihood of exploitation is unknown, but the potential impact is severe.
OpenCVE Enrichment