HiJiffy Chatbot Incorrect Authorization Vulnerability Allowing Unauthorized Message Access

Vulnerability

An incorrect authorization vulnerability has been identified in the HiJiffy Chatbot, which is used for guest communications. This vulnerability allows attackers to access private messages from other users by exploiting the 'visitor' parameter in the '/api/v1/webchat/message' endpoint.

Impact

Exploitation of this vulnerability allows for unauthorized access to private messages of other users.

Remediation

Users are advised to update to the latest available version of the HiJiffy Chatbot.

Added: Mar 26, 2026, 10:18 AM
Updated: Mar 26, 2026, 10:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
4.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.