CVE-2025-48932

Invision Community 4.7.20 - (calendar/view.php) SQL Injection

STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2025-48932. PoCs published by Egidio Romano, XploitGh0st, CerberusMrXi.

AI-analyzed exploit summary The vulnerability is a SQL injection flaw in Invision Community's calendar module, specifically in the `location` parameter of the `view.php` script. It allows unauthenticated attackers to perform boolean-based SQL injection attacks, potentially leading to sensitive data exposure.

Description

Invision Community 4.7.20 - (calendar/view.php) SQL Injection

Exploits (3)

exploitdb WRITEUP VERIFIED
by Egidio Romano · textwebappsmultiple
https://www.exploit-db.com/exploits/52383

The vulnerability is a SQL injection flaw in Invision Community's calendar module, specifically in the `location` parameter of the `view.php` script. It allows unauthenticated attackers to perform boolean-based SQL injection attacks, potentially leading to sensitive data exposure.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Invision Community <= 4.7.20
No auth needed
Prerequisites: Calendar application installed · GeoLocation feature configured
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by XploitGh0st · poc
https://github.com/XploitGh0st/CVE-2025-48932---exploit

This repository contains a functional Python exploit for CVE-2025-48932, targeting an SQL injection vulnerability in Invision Community software. The exploit includes automated CSRF token extraction, boolean-based blind SQL injection, and admin password reset capabilities.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Invision Community
No auth needed
Prerequisites: Network access to vulnerable Invision Community instance · Python 3.7+ environment
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →
github WORKING POC
by CerberusMrXi · pythonpoc
https://github.com/CerberusMrXi/CVE-2025-48932-Invision-Community-SQLi-Exploit

This repository contains a functional Python exploit for CVE-2025-48932, an unauthenticated SQL injection vulnerability in Invision Community <= 4.7.20. The exploit includes boolean-based and time-based injection techniques, multi-threaded data extraction, and database enumeration capabilities.

Classification
Working Poc 98%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Invision Community 4.6.0 - 4.7.20
No auth needed
Prerequisites: Network access to the target Invision Community instance · Calendar application must be accessible and enabled
mistral-large-3 · analyzed Aug 02, 2026 Full analysis →

Details

Status draft
Tracked Since Feb 18, 2026