ChatVia Themesbrand ChatVia Vulnerabilites Broken Object Level Authorization: Capture any other user IDs through a user search request. Capture image upload request. (below image) Replace other user id with your id and send the request. Malicious File Upload: Capture profile image upload request and then chane the type and content to upload html file (containing javascript code). Below image is the url of uploaded file.