Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recipients' Parameter (CVE-2026-12918) | HOL Guard CVE