Vulnerability Description
An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Group-Office | Group Office | < 6.8.136 |
Related Weaknesses (CWE)
References
- https://github.com/WinDyAlphA/CVE-2025-63406-PoCExploit
- https://noahheraud.com/posts/CVE-2025-63406/ExploitThird Party Advisory
FAQ
What is CVE-2025-63406?
CVE-2025-63406 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php
How severe is CVE-2025-63406?
CVE-2025-63406 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63406?
Check the references section above for vendor advisories and patch information. Affected products include: Group-Office Group Office.