CVE-2025-52026
HIGHAptsys Gemscms Backend < 2025-05-28 - Information Disclosure
Title source: ruleDescription
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.
Scores
CVSS v3
7.5
EPSS
0.0001
EPSS Percentile
2.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-200
CWE-327
Status
published
Affected Products (1)
aptsys/gemscms_backend
< 2025-05-28
Timeline
Published
Jan 23, 2026
Tracked Since
Feb 18, 2026