SQL Injection Vulnerability in Xiongwei Smart Catering Cloud Platform by Hangzhou Xiongwei Technology Development Co., Ltd.
CVE-2025-14780
Key Information:
- Vendor
Xiongwei
- Vendor
- CVE Published:
- 16 December 2025
Badges
What is CVE-2025-14780?
A security vulnerability has been identified in the Xiongwei Smart Catering Cloud Platform 2.1.6446.28761, where an unknown function located in the /dishtrade/dish_trade_detail_get file is susceptible to SQL injection. This flaw allows attackers to manipulate the argument filter, enabling unauthorized remote access and potential data breaches. The exploit is publicly available, heightening the urgency for affected users to implement mitigations.
Affected Version(s)
Smart Catering Cloud Platform 2.1.6446.28761
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
