tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-20790.json"