Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20298
Reference (s):
- https://y4er.com/post/zzzphp-rce/

