Junglewise Threat Intelligence

CVE-2025-52024: Aptsys gemscms POS Platform authentication bypass in Web Services module

CVE-2025-52024 · Severity: critical · CVSS 9.4 · Published 2026-01-23

Technologies: Aptsys Gemscms Backend. Vendors: Aptsys.

Executive brief

Aptsys POS Platform, a system used for managing point-of-sale transactions and restaurant operations, contains a security flaw that exposes internal developer tools to the public internet. An unauthorized person can access these tools to view and execute sensitive commands, such as adjusting customer credits, retrieving transaction history, and performing internal data queries. This could lead to financial fraud, theft of customer data, and significant disruption to business operations.

Technical details

A security misconfiguration in the Aptsys gemscms POS Platform Web Services module allows unauthenticated access to internal developer testing panels. These panels, accessible via predictable URL paths in production environments, provide a directory-style index of backend services and HTML forms for submitting test input. A remote attacker can use these interfaces to discover and execute sensitive API endpoints without any session validation or authentication. Impacted functions include user transaction retrieval, credit adjustments, POS actions, and internal database queries. As of the advisory date, the vendor has not acknowledged the issue, and it remains unpatched.

Affected products

  • Aptsys gemscms POS Platform Web Services through 2025-05-28

Timeline

  • 2025-04-01: other: Vulnerability discovered
  • 2025-05-01: other: Vendor notified repeatedly through November 2025
  • 2025-07-01: other: CVE reserved
  • 2025-11-18: disclosed: Public disclosure via GitHub Gist
  • 2026-01-23: advisory: NVD advisory published

References

Related threats