CVE-2025-14317

In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-01-14 14:16

Updated : 2026-01-14 16:25


NVD link : CVE-2025-14317

Mitre link : CVE-2025-14317

CVE.ORG link : CVE-2025-14317


JSON object : View

Products Affected

No product.

CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor