← Vulnerability feed

Vulnerability record · CVE-2025-52022 · published 23 January 2026

CVE-2025-52022: Aptsys gemscms backend error message information leak vulnerability

Aptsys · Gemscms Backend

A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests are sent to public API endpoints, exposing potentially sensitive information useful for further exploitation. This issue is classified under CWE-209: Information Exposure Through an Error Message.

5.3 CVSS 3.1 Medium EPSS 0.45% · top 63.2% CWE-209 · Error message information leak
5.3CVSS 3.1 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
5 Jul 2026Last modified by NVD

Description

A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests are sent to public API endpoints, exposing potentially sensitive information useful for further exploitation. This issue is classified under CWE-209: Information Exposure Through an Error Message.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-52022 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2025-52024Aptsys gemscms backend missing authentication for critical function vulnerabilityA vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated us…EPSS 0.46%9.4CVE-2025-52025Aptsys gemscms backend sql injection vulnerabilityAn SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulner…EPSS 0.37%7.5CVE-2025-52026Aptsys gemscms backend information exposure vulnerabilityAn information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. Th…EPSS 0.31%5.3CVE-2025-52023Aptsys gemscms backend error message information leak vulnerabilityA vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error message…EPSS 0.45%4.3CVE-2025-47813Wing FTP Server path disclosure via long UID cookieWing FTP Server before 7.4.4 leaks the full local installation path through loginok.html when a long value is supplied in the UID cookie. The flaw is…KEVEPSS 63%analysed7.5CVE-2024-29059Microsoft .NET Framework error message information disclosureCVE-2024-29059 is an information disclosure flaw in Microsoft .NET Framework, classified as CWE-209 (error message information leak). A remote, unaut…KEVEPSS 99%analysed6.5CVE-2013-7331Microsoft XMLDOM ActiveX control in Internet Explorer leaks local and intranet path informationThe Microsoft.XMLDOM ActiveX control in Internet Explorer on Windows 8.1 and earlier discloses whether local pathnames, UNC share pathnames, intranet…KEVEPSS 50%analysed

Source: NIST National Vulnerability Database (record CVE-2025-52022), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.