Filtered by vendor Emaintenance Subscriptions
Filtered by product Crazy Bubble Tea Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-14317 1 Emaintenance 1 Crazy Bubble Tea 2026-01-15 N/A
In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).