CyberRota Analysis
This vulnerability has an unknown severity rating. It affects Android. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-14317
Severity
UNKNOWN
CVSS
N/A
EPSS
0.25%
Android
Original NVD Description
In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).