option_Update.asp in Carbon Communities 2.4 and earlier allows remote attackers to edit arbitrary member information via a modified ID field.
https://exchange.xforce.ibmcloud.com/vulnerabilities/41961
http://www.securityfocus.com/archive/1/490923/100/0/threaded