Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting (CVE-2026-100882) | HOL Guard CVE