CVE-2025-52026 is an information disclosure vulnerability in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform. This unauthenticated endpoint exposes cashier account details, including MD5-hashed passwords, which are easily reversible to plaintext. Rated 7.5 HIGH, this vulnerability allows remote attackers to gain unauthorized access to sensitive POS operations or backend functions due to the weak cryptographic hashing. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the high FAUCET Risk Score of 91/100 indicates a significant potential for impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-05-28CPE matchmatch criteria | cpe:2.3:a:aptsys:gemscms_backend:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.