← Vulnerability feed

Vulnerability record · CVE-2019-10647 · published 30 March 2019

CVE-2019-10647: Zzzcms zzzphp unrestricted file upload vulnerability

Zzzcms · Zzzphp

ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.php can be used if the 192.168.0.1 web server sends the contents of a .php file (i.e., it does not interpret a .php file).

9.8 CVSS 3.0 Critical EPSS 6.6% · top 6.4% CWE-434 · Unrestricted file upload
9.8CVSS 3.0 base score, v2 7.5
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.php can be used if the 192.168.0.1 web server sends the contents of a .php file (i.e., it does not interpret a .php file).

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-10647 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-9082ThinkPHP invokefunction parameter allows remote command executionThinkPHP before 3.2.4, and products built on it such as Open Source BMS v1.1.1, fails to properly restrict the invokefunction route, letting a crafte…KEVEPSS 97%analysed9.8CVE-2022-23881ZZZCMS zzzphp danger_key() remote command executionZZZCMS zzzphp v2.1.0 contains a remote command execution flaw reached through the danger_key() function in zzz_template.php. The CVSS 3.1 base score …EPSS 57%analysed9.8CVE-2021-32605Zzzcms zzzphp os command injection vulnerabilityzzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, …EPSS 3.8%9.8CVE-2020-24877Zzzcms zzzphp sql injection vulnerabilityA SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.EPSS 2.1%9.8CVE-2020-18717Zzzcms zzzphp sql injection vulnerabilitySQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.EPSS 3.6%9.8CVE-2020-20298Zzzcms zzzphp code injection vulnerabilityEval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to ex…EPSS 2.7%9.8CVE-2019-17408Zzzcms zzzphp code injection vulnerabilityparserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be…EPSS 3.7%9.8CVE-2019-16722Zzzcms zzzphp vulnerabilityZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2019-10647), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.