HiJiffy Chatbot Incorrect Authorization Vulnerability Allowing Unauthorized Message Downloads

Vulnerability

An incorrect authorization vulnerability in HiJiffy Chatbot enables attackers to download private messages from other users. This is achieved by exploiting the 'ID' parameter in the '/api/v1/download/<ID>/' endpoint.

Impact

Exploitation of this vulnerability allows for unauthorized access to and downloading of private messages from other users.

Remediation

Users are advised to update to the latest available version of HiJiffy Chatbot.

Added: Mar 26, 2026, 10:18 AM
Updated: Mar 26, 2026, 10:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
4.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.