{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/yii2-starter-kit/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yii2-starter-kit:yii2-starter-kit:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-103475"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["yii2-starter-kit (\u003c= 4.2.0)"],"_cs_severities":["critical"],"_cs_tags":["web-application","misconfiguration","rce","information-disclosure","file-upload","vulnerability"],"_cs_type":"advisory","_cs_vendors":["yii2-starter-kit"],"content_html":"\u003cp\u003eyii2-starter-kit versions through 4.2.0 contain a critical configuration vulnerability (CVE-2026-103475) that leaves the Yii debug and Gii modules exposed to all IP addresses. By default, the application sets the 'allowedIPs' parameter to ['*'], enabling unauthenticated remote access to these administrative endpoints.\u003c/p\u003e\n\u003cp\u003eThe debug module allows unauthorized users to view sensitive application internals, including session cookies, environment variables, and database query logs, facilitating further attacks or account takeovers. The Gii module is a code generation tool that allows users to create and write PHP files directly into the application directory. Attackers can leverage this functionality to perform remote code execution by injecting and executing arbitrary PHP code. Because these endpoints are often exposed without requiring authentication in this misconfigured state, an attacker needs only network reachability to the web application to achieve full system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify applications running yii2-starter-kit by fingerprinting web headers or file paths.\u003c/li\u003e\n\u003cli\u003eAttacker probes for the presence of the Yii debug module via common paths such as /debug/default/index.\u003c/li\u003e\n\u003cli\u003eAttacker accesses the exposed debug endpoint to harvest sensitive data, including session cookies and database credentials found in logs.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the Gii module endpoint, typically located at /gii.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes Gii code generation features to create a new controller or model containing arbitrary PHP malicious payloads.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the writing of the crafted PHP file into the application's source directory.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the newly created file URL to trigger code execution.\u003c/li\u003e\n\u003cli\u003eFinal objective achieved: remote command execution leading to full application control or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to obtain sensitive information, including session identifiers and database contents, or achieve remote code execution by injecting arbitrary PHP files into the application directory. This affects all deployments of yii2-starter-kit versions 4.2.0 and earlier using the default development configuration, potentially impacting any organization running this starter kit in a production environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately audit all instances of yii2-starter-kit to identify if the development configuration is active in production.\u003c/li\u003e\n\u003cli\u003eRestrict access to /debug and /gii endpoints via web server configuration (e.g., Nginx/Apache) or by updating the application configuration to limit 'allowedIPs' to trusted internal addresses.\u003c/li\u003e\n\u003cli\u003eUpdate yii2-starter-kit to a version that enforces secure default configurations, or explicitly disable the debug and Gii modules in production environments.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP requests directed at /debug/* or /gii/* paths originating from unauthorized external IP addresses.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T18:36:38Z","date_published":"2026-09-30T18:35:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-yii2-starter-kit-misconfig/","summary":"Versions of yii2-starter-kit up to 4.2.0 are vulnerable to unauthorized access due to insecure default configurations allowing remote attackers to access debugging and code generation modules.","title":"Unauthenticated Exposure of Yii Debug and Gii Modules in yii2-starter-kit","url":"https://feed.craftedsignal.io/briefs/2026-09-yii2-starter-kit-misconfig/"}],"language":"en","title":"CraftedSignal Threat Feed - Yii2-Starter-Kit","version":"https://jsonfeed.org/version/1.1"}