cPanel prior to 62.0.17 allows arbitrary code execution during account modification (SEC-220).
cpanel cpanel