High severity8.8NVD Advisory· Published Nov 13, 2025· Updated Jun 17, 2026
CVE-2025-63406
CVE-2025-63406
Description
An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:*range: <6.8.136
- (no CPE)range: <25.0.47, <6.8.136
- Intermesh BV/GroupOfficedescription
Patches
Vulnerability mechanics
References
1- noahheraud.com/posts/CVE-2025-63406/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.