'visitor' in '/api/v1/webchat/message'.
No advisories yet.
Solution
The vulnerabilities have been resolved by the HiJiffy team. Since the affected product is a cloud-based solution, the fix has already been deployed across all online versions, so no further action is required on the part of users.
Workaround
No workaround given by the vendor.
Thu, 26 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'visitor' in '/api/v1/webchat/message'. | |
| Title | Incorrect authorization in HiJiffy Chatbot | |
| First Time appeared |
Hijiffy
Hijiffy hijiffy Chatbot |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:hijiffy:hijiffy_chatbot:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Hijiffy
Hijiffy hijiffy Chatbot |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-06-09T08:58:49.098Z
Reserved: 2026-03-16T12:00:03.903Z
Link: CVE-2026-4263
Updated: 2026-03-26T14:02:29.524Z
Status : Deferred
Published: 2026-03-26T10:16:26.173
Modified: 2026-05-19T15:43:28.500
Link: CVE-2026-4263
No data.
OpenCVE Enrichment
Updated: 2026-03-27T08:36:19Z