User Access Manager <= 2.3.18 - Reflected Cross-Site Scripting via 'tab_group_section' Parameter (CVE-2026-19797) | HOL Guard CVE