The report module in vtiger CRM prior to 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries.
vtiger vtiger crm