When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which includes sensitive database backup files.
View the template here CVE-2021-20114.yaml
References:
https://github.com/ARPSyndicate/cvemon