Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter
'visitor' in '/api/v1/webchat/message'.
'visitor' in '/api/v1/webchat/message'.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
Update the product to the latest version.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Mar 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'visitor' in '/api/v1/webchat/message'. | |
| Title | Incorrect authorization in HiJiffy Chatbot | |
| First Time appeared |
Hijiffy
Hijiffy hijiffy Chatbot |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:hijiffy:hijiffy_chatbot:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Hijiffy
Hijiffy hijiffy Chatbot |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-26T09:29:07.251Z
Reserved: 2026-03-16T12:00:03.903Z
Link: CVE-2026-4263
No data.
Status : Received
Published: 2026-03-26T10:16:26.173
Modified: 2026-03-26T10:16:26.173
Link: CVE-2026-4263
No data.
OpenCVE Enrichment
No data.
Weaknesses