HiJiffy Chatbot Incorrect Authorization Vulnerability Allowing Unauthorized Message Downloads
Vulnerability
An incorrect authorization vulnerability in HiJiffy Chatbot enables attackers to download private messages from other users. This is achieved by exploiting the 'ID' parameter in the '/api/v1/download/<ID>/' endpoint.
Impact
Exploitation of this vulnerability allows for unauthorized access to and downloading of private messages from other users.
Remediation
Users are advised to update to the latest available version of HiJiffy Chatbot.
Added: Mar 26, 2026, 10:18 AM
Updated: Mar 26, 2026, 10:18 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
0.0relevance
4.8threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
