cPanel prior to 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
cpanel cpanel