CVE 6.9 MEDIUM

Name and e-mail of employee that has done a publication is discoverable in gpp-burgerportaal_CVE-2025-62362

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Description

gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name and email address of employees who publish content are exposed in network responses and can be discovered by viewing the browser's developer tools network tab. This information disclosure may violate employee privacy expectations and could be used for targeted attacks or unwanted contact. This issue has been patched in versions 2.0.3, 3.0.2, and 4.0.1. No known workarounds exist.

Basic Information

ID CVE-2025-62362
Source GitHub_M
Published Oct 13, 2025 at 21:33

Affected Product

Vendor GPP-Woo
Product GPP-burgerportaal
Version < 2.0.3
Affected Versions GPP-Woo GPP-burgerportaal < 2.0.3
GPP-Woo GPP-burgerportaal >= 3.0.0-rc.0, < 3.0.2
GPP-Woo GPP-burgerportaal >= 4.0.0-rc.0, < 4.0.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.