CVE-2026-103474: yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Validate uploaded file types in the backend storage upload actions and prevent authenticated managers from uploading PHP scripts.
yii2-starter-kit backend storage upload actions file type validation = Disallow PHP files
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated account with the manager role. The upload actions are in the backend storage functionality, so unauthenticated users are not described as able to exploit it.
What access does successful exploitation provide?
A manager can upload a PHP script into the web-accessible storage directory and request it, resulting in arbitrary code execution on the server. The listed impact includes high confidentiality, integrity, and availability impact.
Which versions are affected?
Trikoder Yii2 Starter Kit through version 4.2.0 is affected.