cPanel prior to 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
cpanel cpanel