Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
- http://seclists.org/fulldisclosure/2021/Dec/3
No PoCs found on GitHub currently.