A vulnerability was found in sdelements Lets Chat up to 0.4.8. It has been rated as problematic. This issue affects some unknown processing of the file app/controllers/files.js of the component File Retrieval. The manipulation of the argument id/name leads to improper access controls. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is referenced as CVE-2026-66750. Remote exploitation of the attack is possible. No exploit is available.

To fix this issue, it is recommended to deploy a patch.