In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.
https://github.com/RaspAP/raspap-webgui/blob/3.0.9/ajax/logging/clearlog.php
https://gist.github.com/1047524396/ab997b902ec892e592a0df93f38e6941