Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation (CVE-2024-22416) | HOL Guard CVE