logo

Vulnerabilities and Information Disclosure in MSP Survey Software | Huntress

ID: a9a90375-23fc-597a-9024-a700058a87db

STIX ID: report--a9a90375-23fc-597a-9024-a700058a87db

Feed Name: Huntress Blog

Threat Score
45/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

Huntress discovered that survey pages generated by Crewhu were returning JSON in HTTP responses that included sensitive integration details—PSA/integration server domain names, usernames, plaintext passwords, and public/private keys. The issue was reported at a conference; Crewhu redacted the exposed values within two hours, engaged Atlantic Data Forensics for deeper assessment, and advised partners to rotate API keys as a precaution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.