Chamilo stored XSS via user registration leads to admin account takeover (CVE-2026-39878) | HOL Guard CVE