<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Yii2-Starter-Kit (&lt;= 4.2.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/yii2-starter-kit--4.2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 18:35:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/yii2-starter-kit--4.2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Exposure of Yii Debug and Gii Modules in yii2-starter-kit</title><link>https://feed.craftedsignal.io/briefs/2026-09-yii2-starter-kit-misconfig/</link><pubDate>Wed, 30 Sep 2026 18:35:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-yii2-starter-kit-misconfig/</guid><description>Versions of yii2-starter-kit up to 4.2.0 are vulnerable to unauthorized access due to insecure default configurations allowing remote attackers to access debugging and code generation modules.</description><content:encoded><![CDATA[<p>yii2-starter-kit versions through 4.2.0 contain a critical configuration vulnerability (CVE-2026-103475) that leaves the Yii debug and Gii modules exposed to all IP addresses. By default, the application sets the 'allowedIPs' parameter to ['*'], enabling unauthenticated remote access to these administrative endpoints.</p>
<p>The debug module allows unauthorized users to view sensitive application internals, including session cookies, environment variables, and database query logs, facilitating further attacks or account takeovers. The Gii module is a code generation tool that allows users to create and write PHP files directly into the application directory. Attackers can leverage this functionality to perform remote code execution by injecting and executing arbitrary PHP code. Because these endpoints are often exposed without requiring authentication in this misconfigured state, an attacker needs only network reachability to the web application to achieve full system compromise.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify applications running yii2-starter-kit by fingerprinting web headers or file paths.</li>
<li>Attacker probes for the presence of the Yii debug module via common paths such as /debug/default/index.</li>
<li>Attacker accesses the exposed debug endpoint to harvest sensitive data, including session cookies and database credentials found in logs.</li>
<li>Attacker navigates to the Gii module endpoint, typically located at /gii.</li>
<li>Attacker utilizes Gii code generation features to create a new controller or model containing arbitrary PHP malicious payloads.</li>
<li>Attacker triggers the writing of the crafted PHP file into the application's source directory.</li>
<li>Attacker navigates to the newly created file URL to trigger code execution.</li>
<li>Final objective achieved: remote command execution leading to full application control or data exfiltration.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to obtain sensitive information, including session identifiers and database contents, or achieve remote code execution by injecting arbitrary PHP files into the application directory. This affects all deployments of yii2-starter-kit versions 4.2.0 and earlier using the default development configuration, potentially impacting any organization running this starter kit in a production environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately audit all instances of yii2-starter-kit to identify if the development configuration is active in production.</li>
<li>Restrict access to /debug and /gii endpoints via web server configuration (e.g., Nginx/Apache) or by updating the application configuration to limit 'allowedIPs' to trusted internal addresses.</li>
<li>Update yii2-starter-kit to a version that enforces secure default configurations, or explicitly disable the debug and Gii modules in production environments.</li>
<li>Review web server logs for HTTP requests directed at /debug/* or /gii/* paths originating from unauthorized external IP addresses.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-application</category><category>misconfiguration</category><category>rce</category><category>information-disclosure</category><category>file-upload</category><category>vulnerability</category></item></channel></rss>