The Configuration Console of Sophos Antivirus version 9.5.1 (Linux) does not sanitize several input parameters before sending them back to the browser, so an attacker could inject code inside these parameters, including JavaScript code.
d5779939070931292b00a87c8ea949ce6bb287c59c479c89bc4cf5e8803265d9