Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration (CVE-2026-54348) | HOL Guard CVE