Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions (CVE-2025-12627) | HOL Guard CVE