backpack/crud: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserver (CVE-2026-54177) | HOL Guard CVE