CVE-2025-14317

In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).
CVSS

No CVSS.

Configurations

No configuration.

History

14 Jan 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 14:16

Updated : 2026-01-14 16:25


NVD link : CVE-2025-14317

Mitre link : CVE-2025-14317

CVE.ORG link : CVE-2025-14317


JSON object : View

Products Affected

No product.

CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor