An XML External Entity (XXE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
View the template here CVE-2022-3980.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2022-3980