index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain profilePrivileges action in the Users module.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Vtiger_crm | Vtiger | * | 5.0.2 (including) |
References