Path Traversal via Unsanitized Upload Filename
baserCMS plugin and theme upload handlers use the client-supplied filename to build a destination path without calling basename(), so an authenticated user can smuggle traversal sequences and write an arbitrary file, including a PHP payload, before any ZIP validation runs. If the webroot is writable this leads to remote code execution; the issue is fixed in version 5.2.3.