Loading
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.
Use CWE-434, Playsms vendor hub and Playsms product page to widen CVE-2017-9101 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-8644, CVE-2022-47034 and CVE-2021-40373 for nearby disclosures in the same product family.