PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
mitre·CWE-94·Published 2020-02-05