Home

Description

An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php

PUBLISHED Reserved 2025-10-27 | Published 2025-11-13 | Updated 2025-11-19 | Assigner mitre

References

noahheraud.com/posts/CVE-2025-63406/

github.com/WinDyAlphA/CVE-2025-63406-PoC

cve.org (CVE-2025-63406)

nvd.nist.gov (CVE-2025-63406)

Download JSON