Aptsys gemscms Backend Verbose Error Message Exposure Vulnerability

Vulnerability

A vulnerability exists in the PHP backend of Aptsys gemscms, affecting versions through May 28, 2025. It allows unauthenticated remote attackers to send specially crafted HTTP GET or POST requests to public API endpoints, triggering detailed error messages that disclose internal file paths, code snippets, and stack traces. This information leakage, classified under CWE-209, could be exploited for further attacks.

Impact

The vulnerability exposes sensitive internal server information, including file paths and code fragments, through unhandled PHP exceptions. This leakage could facilitate subsequent exploitation attempts, such as SQL injection, local file inclusion, or remote code execution, and increase the attack surface for enumeration.

Reproduction

The vulnerability can be reproduced by sending malformed HTTP GET or POST requests to public API endpoints on the Aptsys gemscms backend. This will trigger unhandled exceptions that expose verbose PHP error messages, including internal file paths, code snippets, and stack traces.

Remediation

To address this vulnerability, disable verbose error reporting in production environments and implement centralized error handling that sanitizes output. Additionally, the vendor should be encouraged to acknowledge and patch the issue.

Added: Jan 23, 2026, 9:21 PM
Updated: Jan 23, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
2.3
threat
1.6
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.