CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page` (CVE-2026-76899) | HOL Guard CVE