CVE-2019-9041
HIGH NUCLEIZZZCMS zzzphp <V1.6.1 - RCE
Title source: llmDescription
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.
Exploits (1)
Nuclei Templates (1)
ZZZCMS 1.6.1 - Remote Code Execution
HIGHby pikpikcu
Scores
CVSS v3
7.2
EPSS
0.8816
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-917
Status
published
Products (1)
zzzcms/zzzphp
1.6.1
Published
Feb 23, 2019
Tracked Since
Feb 18, 2026