GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.
https://www.gdidees.eu/cms-1-0.html
https://github.com/chamilo/pclzip
https://gist.github.com/Hadi999/d691e35d4f494d37ccc5638e68227606