CVE-2022-4934: Sophos Web Appliance

High severity, CVSS 7.2. EPSS: 1.8% chance of exploitation in the next 30 days.

A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.

Affected products

  • Sophos Web Appliance: before 4.3.10.4 (fixed in 4.3.10.4)

Published 2023-04-04. Last modified 2026-06-17.