CVE-2026-33715
chamilo chamilo-lms, chamilo lms
Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without authentication on fully installed instances because, unlike other AJAX endpoints, it does not include the global.inc.php file that performs authentication and installation-completed checks. Its test_mailer action accepts an arbitrary Symfony Mailer DSN string from POST data and uses it to connect to an attacker-specified SMTP server, enabling Server-Side Request Forgery (SSRF) into internal networks via the SMTP protocol. An unauthenticated atta...
- CVSS
- 7.2
- EPSS
- 0.21% 11.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.15