CVE-2022-4934

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
04/04/2023
Last modified:
11/02/2025

Description

A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sophos:web_appliance:*:*:*:*:*:*:*:* 4.3.10.4 (excluding)