cPanel prior to 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
cpanel cpanel