goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files (CVE-2026-31843) | HOL Guard CVE