index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain profilePrivileges action in the Users module.Referenceshttp://trac.vtiger.com/cgi-bin/trac.cgi/ticket/2237http://trac.vtiger.com/cgi-bin/trac.cgi/report/9