Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter (CVE-2026-15335) | HOL Guard CVE