An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or parameterization. This allows an attacker to inject and execute arbitrary SQL code by submitting crafted input in the id parameter, leading to unauthorized data access or modification.
References
| Link | Resource |
|---|---|
| http://aptsys.com | Product |
| https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39 | Third Party Advisory Mitigation |
Configurations
History
11 Feb 2026, 19:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:aptsys:gemscms_backend:*:*:*:*:*:*:*:* | |
| First Time |
Aptsys
Aptsys gemscms Backend |
|
| References | () http://aptsys.com - Product | |
| References | () https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39 - Third Party Advisory, Mitigation |
26 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.4 |
| CWE | CWE-89 |
23 Jan 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-23 21:15
Updated : 2026-02-11 19:24
NVD link : CVE-2025-52025
Mitre link : CVE-2025-52025
CVE.ORG link : CVE-2025-52025
JSON object : View
Products Affected
aptsys
- gemscms_backend
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
