CVE-2025-14317

CVSS

No CVSS.

I

n Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).

Configurations

No configuration.

History

14 Jan 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 14:16

Updated : 2026-01-14 16:25


NVD link : CVE-2025-14317

Mitre link : CVE-2025-14317

CVE.ORG link : CVE-2025-14317


JSON object : View

Products Affected

No product.

CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor