Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.