CVE-2026-103475 Details
Description
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.
A vulnerability exists in Yii2 Starter Kit versions through 4.2.0, where the Yii debug and Gii modules are exposed to all IP addresses. This is due to the default development configuration allowing all IPs. Unauthenticated remote attackers can access the debug module to retrieve sensitive information such as session cookies and database queries, or use the Gii module to generate and write PHP files into the application directory.
To address this vulnerability, restrict the allowed IPs for the debug and Gii modules to localhost. Additionally, ensure that the application is not running in a development environment on production servers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/yii-starter-kit/yii2-starter-kit | [email protected] | ProductVendor |
| https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/common/config/web.php#L21 | [email protected] | Source CodeVendor |
| https://github.com/yii-starter-kit/yii2-starter-kit/issues/797 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-debug-and-gii-module-exposure | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-489 | Active Debug Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| yii2-starter-kit | <= 4.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion