Junglewise Threat Intelligence

CVE-2026-33715: Chamilo LMS SSRF and open email relay in install.ajax.php

CVE-2026-33715 · Severity: high · CVSS 7.2 · Published 2026-04-14

Technologies: Chamilo Lms. Vendors: Chamilo.

Executive brief

Chamilo LMS, a popular open-source learning management system, contains a security flaw that allows unauthorized individuals to use the server as a tool for sending spam or phishing emails. By exploiting an unprotected installation script, attackers can make emails appear as if they are coming from the organization's official server, damaging its reputation. Additionally, attackers can use this flaw to probe the organization's internal network, potentially discovering other private systems and services.

Technical details

An authentication bypass exists in Chamilo LMS 2.0-RC.2 because the 'install.ajax.php' endpoint fails to include 'global.inc.php', which normally enforces authentication and installation-status checks. An unauthenticated remote attacker can invoke the 'test_mailer' action and provide an arbitrary Symfony Mailer DSN string via POST data. This allows the attacker to force the server to connect to any SMTP server (SSRF) or use the server as an open relay to send unauthorized emails. This can lead to internal network reconnaissance via SMTP error messages or the weaponization of the server for phishing campaigns. The issue is resolved in version 2.0.0-RC.3.

Affected products

  • Chamilo Chamilo LMS 2.0-RC.2

Timeline

  • 2026-04-14: advisory: Vendor advisory published via GitHub
  • 2026-04-14: disclosed
  • 2026-04-14: patched: Fixed in version 2.0.0-RC.3

References

Related threats