The reported issue, related to unauthorized file uploads has been fixed and released in v4.5.4, uploads to the reported directory can only be done by an admin user.
Could you please let me know the version of rtMedia you are currently using? We will be doing an audit on the upload code, to make sure nothing is missed.