yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.7epss 0.4%
probabilidad de explotación
0.4%top 69% de las CVE
explotación observada
noninguna fuente lo reporta
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
yii2-starter-kit · yii2-starter-kitReferencias
https://github.com/yii-starter-kit/yii2-starter-kithttps://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/backend/modules/file/controllers/StorageController.php#L36https://github.com/yii-starter-kit/yii2-starter-kit/issues/797https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unrestricted-file-upload-rce