Responsive FileManager before version 9.13.4 is vulnerable to local file inclusion via filemanager/ajax_calls.php because it uses external input to construct a pathname that should be within a restricted directory, aka local file inclusion.
View the template here CVE-2018-15535.yaml
References:
https://www.exploit-db.com/exploits/45271/