cPanel prior to 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
cpanel cpanel