CVE-2017-17640: Advanced World Database Project Advanced World Database

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.

Affected products

Published 2017-12-13. Last modified 2026-06-17.