Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
https://www.exploit-db.com/exploits/51309
https://harkenzo.tlstickle.com/2023-03-17-UR-Web-Triggerable-RCE/