Icegram Mailer <= 1.0.12 - Authenticated (Administrator+) SQL Injection via 'fields' Parameter (CVE-2026-15951) | HOL Guard CVE