S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-9041 Scanner

Detects 'Code Injection' vulnerability in ZZZCMS affects v. 1.6.1.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-9041
7.2
CVSS

An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ZZZCMS is a content management system used for building and managing websites. It is written in PHP and, just like other CMSs, it allows developers to create web pages without having to write all the code from scratch. This fully-featured, open-source CMS provides admin panels, templates, and various plugins, making it easy to use by both developers and non-technical users.

However, a vulnerability has been discovered in ZZZCMS's zzzphp V1.6.1 version, identified as CVE-2019-9041. The vulnerability resides in the inc/zzz_template.php file, where the parserIfLabel() function's filtering is not strict. This results in the execution of PHP code, allowing attackers to take control of the website and access sensitive data. 

If exploited, the vulnerability can do more harm than just causing website data breaches. Attackers can use it to deploy malware on the website, redirect visitors to malicious sites, or even launch DDOS attacks. Furthermore, this vulnerability highlights how crucial it is to maintain updated and secure versions of CMSs. 

As a platform that promotes digital asset security, s4e.io can help you learn about vulnerabilities in your digital assets, including your ZZZCMS website. With pro features, you can get a comprehensive report on your website's vulnerabilities and how to resolve them. By leveraging such tools and services, you can protect your digital assets from potential vulnerabilities and improve your website's overall security posture. 

 

REFERENCES

Solution Advice

Taking certain precautions can minimize the risks associated with this vulnerability. Here are some measures that can be taken to make ZZZCMS more secure:

  • Update ZZZCMS to the latest version.
  • Restrict access to sensitive directories and files on the server.
  • Implement security controls, such as firewalls and intrusion detection systems.
  • Perform regular scanning and testing on the website.
  • Disable any unused third-party plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-9041 scanner - Code Injection vulnerability in ZZZCMS | S4E