In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data.
This issue was fixed in version 915 (Android) and 7.4.1 (iOS).
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-14 14:16
Updated : 2026-01-14 16:25
NVD link : CVE-2025-14317
Mitre link : CVE-2025-14317
CVE.ORG link : CVE-2025-14317
JSON object : View
Products Affected
No product.
CWE
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
