An XML External Entity (XXE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
id: CVE-2022-3980
info:
name: Sophos Mobile managed on-premises - XML External Entity Injection
...