Information Disclosure Vulnerability in gpp-burgerportaal by Dutch Government
CVE-2025-62362

6.9MEDIUM

Key Information:

Vendor

Gpp-woo

Vendor
CVE Published:
13 October 2025

What is CVE-2025-62362?

The gpp-burgerportaal, a Dutch government citizen portal, exhibits an information disclosure vulnerability affecting versions prior to 2.0.3, 3.0.2, and 4.0.1. This flaw allows the exposure of employee names and email addresses in network responses, accessible through the browser's developer tools network tab. Such disclosures can jeopardize employee privacy and potentially facilitate targeted attacks or unsolicited contact with affected individuals. The issue has been rectified in the aforementioned versions, and no known workarounds are available.

Affected Version(s)

GPP-burgerportaal < 2.0.3 < 2.0.3

GPP-burgerportaal >= 3.0.0-rc.0, < 3.0.2 < 3.0.0-rc.0, 3.0.2

GPP-burgerportaal >= 4.0.0-rc.0, < 4.0.1 < 4.0.0-rc.0, 4.0.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62362 : Information Disclosure Vulnerability in gpp-burgerportaal by Dutch Government