GHSA-75rg-6mfq-67qwMediumCVSS 5.3
yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment...
🔗 CVE IDs covered (1)
📋 Description
yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-103476
- https://github.com/yii-starter-kit/yii2-starter-kit/issues/797
- https://github.com/yii-starter-kit/yii2-starter-kit
- https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/frontend/controllers/ArticleController.php#L69
- https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unauthorized-file-download-via-attachment-download
- https://github.com/advisories/GHSA-75rg-6mfq-67qw