CVE Database
/

CVE-2025-14317

Back to search

CVE-2025-14317

Published: Jan 14, 2026

Modified: Jan 14, 2026

PUBLISHED

Description

In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).

VendorProductVersions

Emaintenance

Crazy Bubble Tea

affected
0 - < 915

Emaintenance

Crazy Bubble Tea

affected
0 - < 7.4.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now