Vulnerabilities and Information Disclosure in MSP Survey Software | Huntress
ID: a9a90375-23fc-597a-9024-a700058a87db
STIX ID: report--a9a90375-23fc-597a-9024-a700058a87db
Feed Name: Huntress Blog
Threat Score
Huntress discovered that survey pages generated by Crewhu were returning JSON in HTTP responses that included sensitive integration details—PSA/integration server domain names, usernames, plaintext passwords, and public/private keys. The issue was reported at a conference; Crewhu redacted the exposed values within two hours, engaged Atlantic Data Forensics for deeper assessment, and advised partners to rotate API keys as a precaution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
