helloGTX Travel Portal CRM version 1.6 suffers from an insecure direct object reference vulnerability.