CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-103475 — yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP a...

·Source: NIST NVD

Updated:

Executive Summary

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.

Analysis

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory. CVSS Score: 9.1. Published: 2026-09-30T18:18:17.817.

Indicators of Compromise (1)

CVE (1)
CVE-2026-103475
Source Attribution

Originally published by NIST NVD on Sep 30, 2026. Verified by: NIST.

Related Threats