CVE-2025-52023 Details
Description
A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests are sent to public API endpoints, exposing potentially sensitive information useful for further exploitation. This issue is classified under CWE-209: Information Exposure Through an Error Message.
A vulnerability exists in the PHP backend of Aptsys gemscms, affecting versions through May 28, 2025. It allows unauthenticated remote attackers to send specially crafted HTTP GET or POST requests to public API endpoints, triggering detailed error messages that disclose internal file paths, code snippets, and stack traces. This information leakage, classified under CWE-209, could be exploited for further attacks.
To address this vulnerability, disable verbose error reporting in production environments and implement centralized error handling that sanitizes output. Additionally, the vendor should be encouraged to acknowledge and patch the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-209 | Generation of Error Message Containing Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| aptsys gemscms backend | <= 2025-05-28 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 11, 2026 | Initial Analysis | [email protected] |
| Jan 26, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | New CVE Received | [email protected] |