Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without authentication on fully installed instances because, unlike other AJAX endpoints, it does not include the global.inc.php file that performs authentication and installation-completed checks. Its test_mailer action accepts an arbitrary Symfony Mailer DSN string from POST data and uses it to connect to an attacker-specified SMTP server, enabling Server-Side Request Forgery (SSRF) into internal networks via the SMTP protocol. An unauthenticated attacker can also abuse this to weaponize the Chamilo server as an open email relay for phishing and spam campaigns, with emails appearing to originate from the server's IP address. Additionally, error responses from failed SMTP connections may disclose information about internal network topology and running services. This issue has been fixed in version 2.0.0-RC.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a README and a single Python proof-of-concept script. The PoC targets CVE-2026-33715 in Chamilo LMS 2.0, specifically the unauthenticated endpoint public/main/inc/ajax/install.ajax.php with action test_mailer. The exploit is straightforward: it sends a POST request with an attacker-controlled Symfony Mailer DSN and email fields, causing the target server to open an SMTP connection to an arbitrary host and attempt to send mail. This provides two main capabilities: SSRF over SMTP to internal or external hosts, and open email relay behavior using the target server as the sender/originating infrastructure. The script uses requests.post() with a 15-second timeout, prints response details, and interprets success, connection errors, HTTP 500 responses, or timeouts as indicators of exploitation. Repository structure is minimal and purpose-built for demonstration rather than automation or framework integration. No advanced payload staging or modularization is present; the exploit is operational but basic, with hardcoded/default SMTP examples and CLI arguments for target URL, SMTP DSN, sender, and recipient.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.