An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php
| Software | From | Fixed in |
|---|---|---|
| group-office / group_office | - | 6.8.136 |
| group-office / group_office | 25.0.1 | 25.0.47 |