ZZZCMS zzzphp V1.6.1 is vulnerable to remote code execution via the inc/zzz_template.php file because the parserIfLabel() function’s filtering is not strict, resulting in PHP code execution as demonstrated by the if:assert substring.
View the template here CVE-2019-9041.yaml
References:
https://github.com/Elsfa7-110/kenzer-templates