Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.