Media Sweep <= 1.1.3 - Authenticated (Administrator+) SQL Injection via 'fields' Parameter (CVE-2026-77824) | HOL Guard CVE