iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.