7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data.
This issue was fixed in version 915 (Android) and 7.4.1 (iOS).
This issue was fixed in version 915 (Android) and 7.4.1 (iOS).
Basic Information
ID
CVE-2025-14317
Source
CERT-PL
Published
Jan 14, 2026 at 13:28
Affected Product
Vendor
Emaintenance
Product
Crazy Bubble Tea
Affected Versions
Emaintenance Crazy Bubble Tea 0
Emaintenance Crazy Bubble Tea 0
Emaintenance Crazy Bubble Tea 0