← volver
CVE-2025-62362

Name and e-mail of employee that has done a publication is discoverable in gpp-burgerportaal

CVSS 6.9 MEDIUMEPSS 0.3%CWE-359
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.9EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
13 oct 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name and email address of employees who publish content are exposed in network responses and can be discovered by viewing the browser's developer tools network tab. This information disclosure may violate employee privacy expectations and could be used for targeted attacks or unwanted contact. This issue has been patched in versions 2.0.3, 3.0.2, and 4.0.1. No known workarounds exist.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Productos afectados
GPP-Woo · GPP-burgerportaal

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →