Unknown · Yii2-Starter-Kit · CVE-2026-103475
**Name of the Vulnerable Software and Affected Versions**
yii2-starter-kit versions prior to 4.2.0
**Description**
The software exposes the Yii debug and Gii modules to all IP addresses by setting the `allowedIPs` variable to `['*']` in the default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data, such as session cookies and database queries, or use the Gii endpoint to generate and write PHP files into the application directory.
**Recommendations**
Update yii2-starter-kit to version 4.2.0 or later.