Unauthenticated Exposure of Yii Debug and Gii Modules in yii2-starter-kit
Versions of yii2-starter-kit up to 4.2.0 are vulnerable to unauthorized access due to insecure default configurations allowing remote attackers to access debugging and code generation modules.
CVE search metadata
CVE search record: CVE-2026-103475. Severity: critical. CVSS: 9.1. KEV: no. Product: yii2-starter-kit (<= 4.2.0). Brief: Unauthenticated Exposure of Yii Debug and Gii Modules in yii2-starter-kit. Brief link: https://feed.craftedsignal.io/briefs/2026-09-yii2-starter-kit-misconfig/
What's new
- 1. added detection rule: Detect CVE-2026-103474 Exploitation - PHP File Upload to Web Storage Sep 30, 18:36 via nvd
yii2-starter-kit versions through 4.2.0 contain a critical configuration vulnerability (CVE-2026-103475) that leaves the Yii debug and Gii modules exposed to all IP addresses. By default, the application sets the 'allowedIPs' parameter to ['*'], enabling unauthenticated remote access to these administrative endpoints.
The debug module allows unauthorized users to view sensitive application internals, including session cookies, environment variables, and database query logs, facilitating further attacks or account takeovers. The Gii module is a code generation tool that allows users to create and write PHP files directly into the application directory. Attackers can leverage this functionality to perform remote code execution by injecting and executing arbitrary PHP code. Because these endpoints are often exposed without requiring authentication in this misconfigured state, an attacker needs only network reachability to the web application to achieve full system compromise.
Attack Chain
- Attacker performs reconnaissance to identify applications running yii2-starter-kit by fingerprinting web headers or file paths.
- Attacker probes for the presence of the Yii debug module via common paths such as /debug/default/index.
- Attacker accesses the exposed debug endpoint to harvest sensitive data, including session cookies and database credentials found in logs.
- Attacker navigates to the Gii module endpoint, typically located at /gii.
- Attacker utilizes Gii code generation features to create a new controller or model containing arbitrary PHP malicious payloads.
- Attacker triggers the writing of the crafted PHP file into the application's source directory.
- Attacker navigates to the newly created file URL to trigger code execution.
- Final objective achieved: remote command execution leading to full application control or data exfiltration.
Impact
Successful exploitation allows unauthenticated remote attackers to obtain sensitive information, including session identifiers and database contents, or achieve remote code execution by injecting arbitrary PHP files into the application directory. This affects all deployments of yii2-starter-kit versions 4.2.0 and earlier using the default development configuration, potentially impacting any organization running this starter kit in a production environment.
Recommendation
- Immediately audit all instances of yii2-starter-kit to identify if the development configuration is active in production.
- Restrict access to /debug and /gii endpoints via web server configuration (e.g., Nginx/Apache) or by updating the application configuration to limit 'allowedIPs' to trusted internal addresses.
- Update yii2-starter-kit to a version that enforces secure default configurations, or explicitly disable the debug and Gii modules in production environments.
- Review web server logs for HTTP requests directed at /debug/* or /gii/* paths originating from unauthorized external IP addresses.
Immediate actions
Scan internal web application inventory for yii2-starter-kit installations
Mitigations
Disable debug and Gii modules or restrict access by IP in application config
CVE-2026-103475
Detection coverage 2
Detect Exploitation Attempts against Yii Debug and Gii Modules
highDetects unauthorized access to Yii framework debugging and code generation endpoints which are exposed in vulnerable yii2-starter-kit configurations.
Detect CVE-2026-103474 Exploitation - PHP File Upload to Web Storage
highDetects potential exploitation of CVE-2026-103474 by identifying POST requests to backend storage upload paths that contain PHP file extensions.
Detection queries are available on the platform. Get full rules →