PT-2026-4529 · Aptsys · Aptsys Pos Platform Web Services
Published
2026-01-23
·
Updated
2026-02-11
·
CVE-2025-52024
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Aptsys POS Platform Web Services versions prior to 2025-05-29
Description
The Aptsys POS Platform Web Services module contains a flaw that allows unauthenticated users to access internal API testing tools. Accessing specific URLs reveals a directory listing of backend services and POS web services, complete with HTML forms for submitting test input. These tools, intended for developers, are accessible in production without authentication or session validation. This allows external actors to discover, test, and execute API endpoints that perform critical functions, including user transaction retrieval, credit adjustments, POS actions, and internal data queries. The affected API endpoints include those for user transaction retrieval, credit adjustments, POS actions, and internal data queries.
Recommendations
Versions prior to 2025-05-29 should be updated.
Fix
Missing Authentication
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aptsys Pos Platform Web Services