cPanel prior to 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
cpanel cpanel