HiJiffy Chatbot Incorrect Authorization Vulnerability Allowing Unauthorized Message Access
Vulnerability
An incorrect authorization vulnerability has been identified in the HiJiffy Chatbot, which is used for guest communications. This vulnerability allows attackers to access private messages from other users by exploiting the 'visitor' parameter in the '/api/v1/webchat/message' endpoint.
Impact
Exploitation of this vulnerability allows for unauthorized access to private messages of other users.
Remediation
Users are advised to update to the latest available version of the HiJiffy Chatbot.
Added: Mar 26, 2026, 10:18 AM
Updated: Mar 26, 2026, 10:18 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
0.0relevance
4.5threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
