medium · CVSS v3 5.3 · CVSS v4 6.9
CVE-2026-103476
yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowin…
Description
yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.
Scores
- Severity
- medium
- CVSS v2
- —
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- —