CVE-2025-14780

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
16/12/2025
Last modified:
16/12/2025

Description

A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknown function of the file /dishtrade/dish_trade_detail_get. The manipulation of the argument filter results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.