CVE-2025-52025

An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or parameterization. This allows an attacker to inject and execute arbitrary SQL code by submitting crafted input in the id parameter, leading to unauthorized data access or modification.
References
Link Resource
https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39 Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:aptsys:gemscms_backend:*:*:*:*:*:*:*:*

History

05 Jul 2026, 02:16

Type Values Removed Values Added
References
  • {'url': 'http://aptsys.com', 'tags': ['Product'], 'source': 'cve@mitre.org'}

17 Jun 2026, 09:35

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección SQL existe en el endpoint GetServiceByRestaurantID del backend de la plataforma POS Aptsys gemscms hasta el 28-05-2025. La vulnerabilidad surge porque la entrada del usuario se inserta directamente en una sintaxis de consulta SQL dinámica sin una sanitización o parametrización adecuadas. Esto permite a un atacante inyectar y ejecutar código SQL arbitrario al enviar una entrada manipulada en el parámetro id, lo que lleva a un acceso o modificación de datos no autorizados.
References () https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39 - Third Party Advisory, Mitigation () https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39 - Mitigation, Third Party Advisory

11 Feb 2026, 19:24

Type Values Removed Values Added
CPE cpe:2.3:a:aptsys:gemscms_backend:*:*:*:*:*:*:*:*
First Time Aptsys
Aptsys gemscms Backend
References () http://aptsys.com - () http://aptsys.com - Product
References () https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39 - () https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39 - Third Party Advisory, Mitigation

26 Jan 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.4
CWE CWE-89

23 Jan 2026, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 21:15

Updated : 2026-07-05 02:16


NVD link : CVE-2025-52025

Mitre link : CVE-2025-52025

CVE.ORG link : CVE-2025-52025


JSON object : View

Products Affected

aptsys

  • gemscms_backend
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')