YouPHPTube Encoder 2.3 is susceptible to a command injection vulnerability which could allow an attacker to compromise the server. These exploitable unauthenticated command injections exist via the parameter base64Url in /objects/getImage.php.
View the template here CVE-2019-5127.yaml
References:
https://github.com/Elsfa7-110/kenzer-templates