Cobbler before 3.3.0 allows log poisoning and resultant remote code execution via an XMLRPC method.
View the template here CVE-2021-40323.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-40323.yaml
References: