cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
- https://documentation.cpanel.net/display/CL/72+Change+Log
No PoCs found on GitHub currently.