cPanel prior to 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
cpanel cpanel