XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.Referenceshttps://github.com/goxr3plus/XR3Player/issues/9https://0dd.zone/2018/10/28/xr3player-XXE/