This module enables you to view the differences between revisions on any entity type.
The module doesn't sufficiently restrict access to non-node entity revision diffs.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to view the entity.