Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes (CVE-2026-55208) | HOL Guard CVE