CVE-2019-9041: Zzzcms Zzzphp

High severity, CVSS 7.2. EPSS: 31.4% chance of exploitation in the next 30 days.

An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.

Affected products

  • Zzzcms Zzzphp: version 1.6.1 only

Published 2019-02-23. Last modified 2026-06-17.