ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration (CVE-2026-54596) | HOL Guard CVE