PT-2026-4529 · Aptsys · Aptsys Pos Platform Web Services

Published

2026-01-23

·

Updated

2026-02-11

·

CVE-2025-52024

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Aptsys POS Platform Web Services versions prior to 2025-05-29
Description The Aptsys POS Platform Web Services module contains a flaw that allows unauthenticated users to access internal API testing tools. Accessing specific URLs reveals a directory listing of backend services and POS web services, complete with HTML forms for submitting test input. These tools, intended for developers, are accessible in production without authentication or session validation. This allows external actors to discover, test, and execute API endpoints that perform critical functions, including user transaction retrieval, credit adjustments, POS actions, and internal data queries. The affected API endpoints include those for user transaction retrieval, credit adjustments, POS actions, and internal data queries.
Recommendations Versions prior to 2025-05-29 should be updated.

Fix

Missing Authentication

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-52024

Affected Products

Aptsys Pos Platform Web Services