SFTPGo has stored XSS via inline parameter on public shares and user file download (CVE-2026-49245) | HOL Guard CVE