CVE-2025-51868: n/a
Severity: Type: vulnerabilityCVE-2025-51868
Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.
CVE-2025-51868: n/a
Unknown
Published: Mon Jul 21 2025 (07/21/2025, 00:00:00 UTC)
Source: CVE Database V5
Description
Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-06-16T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
Threat ID: 687ea00aa83201eaac13ae4c
Added to database: 7/21/2025, 8:16:10 PM
Last updated: 7/21/2025, 8:16:10 PM
Views: 1
Related Threats
CVE-2025-7938: Authorization Bypass in jerryshensjf JPACookieShop 蛋糕商城JPA版
MediumVulnerabilityMon Jul 21 2025
CVE-2025-54121: CWE-770: Allocation of Resources Without Limits or Throttling in encode starlette
MediumVulnerabilityMon Jul 21 2025
CVE-2025-54071: CWE-434: Unrestricted Upload of File with Dangerous Type in rommapp romm
CriticalVulnerabilityMon Jul 21 2025
CVE-2025-7231: CWE-787: Out-of-bounds Write in INVT VT-Designer
HighVulnerabilityMon Jul 21 2025
CVE-2025-7230: CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') in INVT VT-Designer
HighVulnerabilityMon Jul 21 2025
Actions
Please log in to the Console to use AI analysis features.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.