cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).Referenceshttps://documentation.cpanel.net/display/CL/60+Change+Log