Impact
An insecure direct object reference in 1millionbot Millie chat allows a remote attacker to alter the conversation ID in the API request and view another user's private conversations without needing any credentials. This vulnerability can expose sensitive or confidential data that was otherwise intended to remain private. The weakness is a common example of identifier exposure, which permits unauthorized data access.
Affected Systems
The affected product is 1millionbot Millie chat. Versions prior to 3.6.0 contain the flaw; the fix is available in the 3.6.0 release.
Risk and Exploitability
The CVSS score of 7 indicates high severity, and while an exploit probability score is not available, the vulnerability can be leveraged simply by knowing a conversation identifier. The ability to read private data without authentication raises substantial risk to confidentiality for all affected users. The vulnerability is not listed in the CISA KeV catalog, but its impact and ease of exploitation make it a significant concern.
OpenCVE Enrichment