In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data.
This issue was fixed in version 915 (Android) and 7.4.1 (iOS).
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS). | |
| Title | User Enumeration in Crazy Bubble Tea mobile application | |
| Weaknesses | CWE-359 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2026-01-14T13:28:02.872Z
Updated: 2026-01-14T13:57:08.343Z
Reserved: 2025-12-09T10:11:51.748Z
Link: CVE-2025-14317
Updated: 2026-01-14T13:57:04.650Z
Status : Awaiting Analysis
Published: 2026-01-14T14:16:11.543
Modified: 2026-01-14T16:25:12.057
Link: CVE-2025-14317
No data.