CVE-2026-103474

Source
https://cve.org/CVERecord?id=CVE-2026-103474
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103474.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103474
Published
2026-09-30T17:22:41Z
Modified
2026-10-02T03:46:59Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE
Details

yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-434"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103474.json"
}
References

Affected packages

Git / github.com/yii-starter-kit/yii2-starter-kit

Affected ranges

Type
GIT
Repo
https://github.com/yii-starter-kit/yii2-starter-kit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "4.2.0"
        },
        {
            "introduced":  "yii2-starter-kit"
        },
        {
            "fixed":  "4.2.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

1.*
1.0.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
2.*
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.3.2
2.5.0
2.5.1
2.5.2
2.6.0
3.*
3.0.0
3.0.1
3.0.3
4.*
4.0.0
4.1.0
v3.*
v3.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103474.json"