CVE-2020-12103
In Tiny File Manager 2.4.1, there is a vulnerability in the ajax file backup copy functionality that allows authenticated users to place backup copies of files (with the .bak extension) into different directories.
Source: CVE-2020-12103