Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2j2-frq6-6v5g

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1

Описание

In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a loyaltyGuestId parameter. Server does not verify the permissions required to obtain the data.

This issue was fixed in version 915 (Android) and 7.4.1 (iOS).

In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a loyaltyGuestId parameter. Server does not verify the permissions required to obtain the data.

This issue was fixed in version 915 (Android) and 7.4.1 (iOS).

EPSS

Процентиль: 10%
0.00034
Низкий

7.1 High

CVSS4

Дефекты

CWE-359

Связанные уязвимости

nvd
25 дней назад

In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).

EPSS

Процентиль: 10%
0.00034
Низкий

7.1 High

CVSS4

Дефекты

CWE-359