Processwire CMS prior to 2.7.1 is vulnerable to local file inclusion because it allows a remote attacker to retrieve sensitive files via the download parameter to index.php.
View the template here CVE-2020-27467.yaml
References:
https://github.com/ARPSyndicate/cvemon