PlaySMS before version 1.4.3 is susceptible to remote code execution because it double processes a server-side template.
View the template here CVE-2020-8644.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-8644.yaml
References: