Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the email address (ID) of another user.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.