If Your users don't absolutely need the ability to save own inboxes then disable the feature because with the right knowledge it is possible to construct an inbox that grants the user executing it admin rights.