Intermesh BV GroupOffice versions before 25.0.47 and 6.8.136 contain a code-injection vulnerability in FunctionField.php. The dbToApi() logic reaches eval(), allowing a remote attacker to execute arbitrary code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python PoC exploit (CVE-2025-63406.py), a README with usage examples, and requirements.txt (requests). Core behavior: - Authenticates to a GroupOffice instance via POST {base_url}/api/auth.php with JSON credentials, then uses returned accessToken (as Cookie) and CSRFToken (as X-CSRF-Token). - Uses the GroupOffice JMAP endpoint {base_url}/api/jmap.php to: 1) Create a FieldSet (FieldSet/set). 2) Create a custom field (Field/set) of type "FunctionField" with databaseName "calc_field" and an injected function string: system('<user_command>'); 42. 3) Trigger evaluation by requesting contacts (Contact/get) and extracting the resulting customFields["calc_field"] value from the first returned contact. Exploit capability: - Provides authenticated remote command execution by injecting a PHP system() call into a function/calculated field definition and then reading the command output back from the API response. Notable implementation details: - The script assumes at least one contact exists (it reads list[0]) and that the custom field key is exactly "calc_field". - It uses a regex to extract a JSON array-of-arrays pattern (\[\[.*\]\]) from response.text before json parsing, rather than directly using response.json() for the Contact/get call. Repository purpose: - A straightforward operational PoC to execute arbitrary system commands on a vulnerable GroupOffice instance using valid credentials, printing the command output to the console.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-63406, targeting the GroupOffice platform. The main file, CVE-2025-63406.py, is a Python script that interacts with the GroupOffice JMAP API endpoint (/api/jmap.php) to exploit a vulnerability in the handling of FieldSet, Field, and Task objects. The exploit authenticates to the target using provided credentials, manipulates API objects, and ultimately injects and triggers a system command on the server by abusing the API's logic. The script includes functions for object creation, deletion, and state extraction, and cleans up after execution. The README.md provides detailed context, usage instructions, and ethical guidelines, emphasizing that the PoC is for research and patch validation in controlled environments. The requirements.txt lists the Python requests library as a dependency. No hardcoded IPs or domains are present; the target endpoint is user-supplied. The exploit is a POC, not weaponized, and demonstrates the vulnerability's impact by achieving remote command execution via authenticated API calls.
This repository contains a Python proof-of-concept exploit for CVE-2025-63406, targeting GroupOffice. The main file, CVE-2025-63406.py, implements an exploit that authenticates to a GroupOffice instance using provided credentials, creates a new FieldSet and a malicious FunctionField that injects and executes arbitrary system commands via the system() function. The exploit then retrieves the output of the command by querying the contacts API and extracting the result from a custom field. The script is fully operational, requiring only the target URL, username, password, and desired command as arguments. The exploit interacts with the GroupOffice API over HTTP, specifically targeting the /api/auth.php and /api/jmap.php endpoints. The repository also includes a README with usage instructions and a requirements.txt listing the 'requests' dependency. No hardcoded endpoints or IPs are present; the base URL is user-supplied. The exploit is not part of a framework and is a standalone operational PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.