VYPR

Gemscms Backend

by Aptsys

CVEs (5)

  • CVE-2025-52025CriJan 23, 2026
    risk 0.61cvss 9.4epss 0.00

    An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or…

  • CVE-2025-52024CriJan 23, 2026
    risk 0.61cvss 9.4epss 0.00

    A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated users. By accessing specific URLs, an attacker is presented with a directory-style index listing all available backend services and…

  • CVE-2025-52026HigJan 23, 2026
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed…

  • CVE-2025-52023MedJan 23, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests…

  • CVE-2025-52022MedJan 23, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST…