Vendor
Versions of yii2-starter-kit up to 4.2.0 are vulnerable to unauthorized access due to insecure default configurations allowing remote attackers to access debugging and code generation modules.