yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.7epss 0.4%
probabilidade de exploração
0.4%top 69% das CVEs
exploração observada
nãonenhuma fonte reporta
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
yii2-starter-kit · yii2-starter-kitReferências
https://github.com/yii-starter-kit/yii2-starter-kithttps://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/backend/modules/file/controllers/StorageController.php#L36https://github.com/yii-starter-kit/yii2-starter-kit/issues/797https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unrestricted-file-upload-rce