CVE-2025-48932

Invision Community 4.7.20 - (calendar/view.php) SQL Injection

STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-48932. PoCs published by Egidio Romano, XploitGh0st.

AI-analyzed exploit summary The vulnerability is a SQL injection flaw in Invision Community's calendar module, specifically in the `location` parameter of the `view.php` script. It allows unauthenticated attackers to perform boolean-based SQL injection attacks, potentially leading to sensitive data exposure.

Description

Invision Community 4.7.20 - (calendar/view.php) SQL Injection

Exploits (2)

exploitdb WRITEUP VERIFIED
by Egidio Romano · textwebappsmultiple
https://www.exploit-db.com/exploits/52383

The vulnerability is a SQL injection flaw in Invision Community's calendar module, specifically in the `location` parameter of the `view.php` script. It allows unauthenticated attackers to perform boolean-based SQL injection attacks, potentially leading to sensitive data exposure.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Invision Community <= 4.7.20
No auth needed
Prerequisites: Calendar application installed · GeoLocation feature configured
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by XploitGh0st · poc
https://github.com/XploitGh0st/CVE-2025-48932---exploit

This repository contains a functional Python exploit for CVE-2025-48932, targeting an SQL injection vulnerability in Invision Community software. The exploit includes automated CSRF token extraction, boolean-based blind SQL injection, and admin password reset capabilities.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Invision Community
No auth needed
Prerequisites: Network access to vulnerable Invision Community instance · Python 3.7+ environment
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status draft
Tracked Since Feb 18, 2026