CVE 6.5 MEDIUM

TSPortal’s Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Service_CVE-2026-33541

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 34, a flaw in TSPortal allowed attackers to create arbitrary user records in the database by abusing validation logic. While validation correctly rejected invalid usernames, a side effect within a validation rule caused user records to be created regardless of whether the request succeeded. This could be exploited to cause uncontrolled database growth, leading to a potential denial of service (DoS). Version 34 contains a fix for the issue.

Basic Information

ID CVE-2026-33541
Source GitHub_M
Published Mar 26, 2026 at 20:27
Modified Mar 27, 2026 at 20:01

Affected Product

Vendor miraheze
Product TSPortal
Version < 34
Affected Versions miraheze TSPortal < 34

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.