Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG (CVE-2026-78337) | HOL Guard CVE