UnoPim versions prior to 2.1.5 contain an authenticated file upload vulnerability in the TinyMCE image upload endpoint. The flaw arises from missing file extension and MIME type validation, allowing authenticated administrators to upload arbitrary PHP files. Attackers can leverage this to upload a PHP web shell to the public storage disk. Once uploaded, the web shell is accessible via the URL returned in the server response, enabling arbitrary operating system command execution. The vulnerability is classified as Remote Code Execution (RCE) via unrestricted file upload. A fix has been issued in UnoPim v2.1.5 via a commit to the official GitHub repository. The issue has been documented by multiple security researchers and advisory sources. Users are strongly advised to upgrade to version 2.1.5 or later immediately.