PT-2025-46893 · Unknown · Group-Office

Published

2025-11-13

·

Updated

2026-01-09

·

CVE-2025-63406

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GroupOffice versions prior to 25.0.47 GroupOffice versions prior to 6.8.136
Description A flaw exists that allows a remote attacker to execute arbitrary code. This is possible through the dbToApi() and eval() functions within the FunctionField.php file.
Recommendations Update GroupOffice to version 25.0.47 or later. Update GroupOffice to version 6.8.136 or later.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-63406

Affected Products

Group-Office