Junglewise Threat Intelligence

CVE-2025-52023: Aptsys GemsCMS information disclosure via verbose error messages

CVE-2025-52023 · Severity: medium · CVSS 5.3 · Published 2026-01-23

Technologies: Aptsys Gemscms Backend. Vendors: Aptsys.

Executive brief

Aptsys GemsCMS, a backend platform used for Point of Sale (POS) and restaurant management systems, contains a vulnerability that reveals sensitive internal technical information to the public. By sending specifically crafted requests, an unauthorized person can force the system to display detailed error messages including server file paths and snippets of the application's code. This information can be used by attackers to better understand the system's internal workings and plan more sophisticated attacks against the business.

Technical details

The Aptsys GemsCMS PHP backend is vulnerable to information disclosure (CWE-209) due to improper error handling on public API endpoints. Unauthenticated remote attackers can trigger unhandled exceptions by sending malformed HTTP GET or POST requests. These exceptions result in verbose PHP error messages that expose sensitive internal server data, including full file system paths, stack traces, and fragments of source code. This information significantly aids an attacker in reconnaissance for further exploits such as SQL injection or remote code execution. As of the disclosure date, the vendor has not released a patch.

Affected products

  • Aptsys GemsCMS Backend thru 2025-05-28

Timeline

  • 2025-05: disclosed: Vulnerability discovered by researcher
  • 2025-05-28: other: End of affected version range identified in advisory
  • 2025-07: other: CVE reserved
  • 2025-11-18: advisory: Public disclosure via GitHub Gist
  • 2026-01-23: other: CVE published to NVD

References

Related threats