cPanel prior to 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
cpanel cpanel