---
id: CVE-2025-52023
title: >-
  A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28
  allows unauthenticated remote attackers to trigger detailed error messages
  that disclose internal file paths, code snippets, and stack traces
summary: >-
  A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28
  allows unauthenticated remote attackers to trigger detailed error messages
  that disclose internal file paths, code snippets, and stack traces. This
  occurs when s…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-209
vendor: aptsys
product: gemscms_backend
affected:
  - gemscms_backend <= 2025-05-28
published: '2026-01-23'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-52023'
references:
  - url: 'https://gist.github.com/ReverseThatApp/4a6be2b9b2ba39d38c35c8753e0afd39'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00453
epssPercentile: 0.38672
ingestedAt: '2026-07-06T16:44:34.517Z'
---

## Overview

A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests are sent to public API endpoints, exposing potentially sensitive information useful for further exploitation. This issue is classified under CWE-209: Information Exposure Through an Error Message.

## Affected

- `gemscms_backend <= 2025-05-28`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
