Loading
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.
Use CWE-94, Playsms vendor hub and Playsms product page to widen CVE-2021-40373 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-8644, CVE-2022-47034 and CVE-2017-9101 for nearby disclosures in the same product family.