VYPR
High severity8.8NVD Advisory· Published Nov 13, 2025· Updated Jun 17, 2026

CVE-2025-63406

CVE-2025-63406

Description

An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:*range: <6.8.136
    • (no CPE)range: <25.0.47, <6.8.136
  • Intermesh BV/GroupOfficedescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.