modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.
Reference Links(if available):
CVSS Score (if available)
v2: / MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
v3: / HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N