Junglewise Threat Intelligence

CVE-2025-52025: Aptsys gemscms SQL injection in GetServiceByRestaurantID

CVE-2025-52025 · Severity: critical · CVSS 9.4 · Published 2026-01-23

Technologies: Aptsys Gemscms Backend. Vendors: Aptsys.

Executive brief

Aptsys gemscms, a backend platform used for Point of Sale (POS) systems, contains a critical security flaw in how it handles restaurant data requests. An attacker can exploit this to run unauthorized database commands, potentially leading to the theft of sensitive customer information, modification of business records, or a complete shutdown of the database service. As of the latest reports, the vendor has not released a fix, leaving systems vulnerable to remote attacks.

Technical details

An SQL injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend. The flaw is caused by the lack of sanitization or parameterization when user-supplied input from the 'id' parameter is concatenated into dynamic SQL queries. A remote, unauthenticated attacker can exploit this by sending crafted HTTP requests to the vulnerable endpoint to execute arbitrary SQL commands. This can result in unauthorized data extraction, modification, or deletion within the backend database. The vulnerability was reported in May 2025 and remains unpatched as the vendor has not acknowledged the researcher's notifications.

Affected products

  • Aptsys gemscms POS Platform backend thru 2025-05-28

Timeline

  • 2025-05-28: disclosed: Vulnerability discovered and initial vendor notification attempted.
  • 2025-07-01: other: CVE reserved.
  • 2025-11-18: advisory: Public disclosure by independent researcher.
  • 2026-01-23: other: CVE published to NVD.

References

Related threats