The fix for CVE-2019-9858 (arbitrary file upload vulnerability) simply restricts the target directory to the temp folder. This, in combination with other vulnerabilities, allows an authenticated regular user to execute PHP and shell code as the user that runs the web server.