Vulnerabilities

Flaws in Software Used by Hundreds of Cities and Towns Exposed Sensitive Data

CERT/CC has disclosed the details of information exposure vulnerabilities in a Workhorse Software application after patches were released. 

CERT/CC has disclosed the details of information exposure vulnerabilities in a Workhorse Software application after patches were released. 

Two potentially serious vulnerabilities have been found by a researcher in accounting software used by hundreds of cities and towns.

The affected application is made by Workhorse Software Services, which provides software solutions to 310 municipalities in Wisconsin. The vendor has released patches and mitigations after being notified.

The vulnerabilities, discovered by researcher James Harrold of Sparrow IT Solutions, were disclosed this week by the CERT Coordination Center (CERT/CC) at Carnegie Mellon University. 

One of the flaws, tracked as CVE-2025-9037, is an information exposure issue related to SQL server connection credentials being stored in a plaintext file that is typically in a shared network folder.

The second issue, CVE-2025-9040, is related to the availability of a database backup feature accessible from the login screen that allows the creation of an unencrypted database backup file, which can later be restored on any SQL server without a password.

This database backup can be copied by anyone with physical access to the device running the Workhorse software, or by malware present on the system.

Advertisement. Scroll to continue reading.

“An attacker could obtain the complete database, potentially exposing sensitive personally identifiable information (PII) such as Social Security numbers, full municipal financial records, and other confidential data,” CERT/CC said. “Possession of a database backup could also enable data tampering, potentially undermining audit trails and compromising the integrity of municipal financial operations.”

Version 1.9.4.48019 patches the vulnerabilities and mitigations are also available. In addition to releasing patches and mitigations, Workhorse pointed out that customers have been responsible for the SQL authentication method used by the software, and the problematic backup functionality has always been optional. 

Related: Flaws in Gigabyte Firmware Allow Security Bypass, Backdoor Deployment

Related: ‘MadeYouReset’ HTTP2 Vulnerability Enables Massive DDoS Attacks

Related: Unpatched Ruckus Vulnerabilities Allow Wireless Environment Hacking

Related Content

Vulnerabilities

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Vulnerabilities

The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.

Vulnerabilities

Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.

Vulnerabilities

The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.

Vulnerabilities

The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.

Vulnerabilities

The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.

Vulnerabilities

Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version