ZZZCMS zzzphp V1.6.1 is vulnerable to remote code execution via the inc/zzz_template.php file because the parserIfLabel() function's filtering is not strict, resulting in PHP code execution as demonstrated by the if:assert substring.
id: CVE-2019-9041
info:
name: ZZZCMS 1.6.1 - Remote Code Execution
author: pikpikcu
severity:
...