CVE-2019-9041: High severity zzzcms vulnerability
Published Feb 23, 2019
·Updated
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzztemplate.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.
Affected Software
1 affected component
ZZZCMS zzzphp=1.6.1
Event History
Feb 23, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-9041.
2
What is the severity level of CVE-2019-9041?
CVE-2019-9041 has a severity level of 7.2 (high).
3
How can the vulnerability be exploited?
The vulnerability can be exploited by executing PHP code through the if:assert substring.
4
Which version of ZZZCMS zzzphp is affected by this vulnerability?
Version 1.6.1 of ZZZCMS zzzphp is affected by this vulnerability.
5
Is there a fix available for this vulnerability?
No specific fix information is provided for this vulnerability. It is recommended to update to a patched version or apply necessary security measures.