CVE-2026-12425
Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Access Center 23.10
Severity
Medium 5.7
CVSS 4.0
Exploited
Not listed
EPSS
0.001
4.6th percentile
Discovered by
Customer
Published by the vendor
Published
Jun 16, 2026
Assigned by palo_alto
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- PowerSchool · Employee Access Center
Credit
Menachem (Momo) Rothbart