Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset (CVE-2025-10308) | HOL Guard CVE