.. / CVE-2022-3980

Exploit for Sophos Mobile managed on-premises - XML External Entity Injection (CVE-2022-3980)

Description:

An XML External Entity (XXE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

Nuclei Template

View the template here CVE-2022-3980.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-3980.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-3980
https://www.sophos.com/en-us/security-advisories/sophos-sa-20221116-smc-xee
https://github.com/bigblackhat/oFx