CVE-2026-12425

Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Access Center 23.10

Severity
Medium 5.7
CVSS 4.0
Exploited
Not listed
EPSS
0.001
4.6th percentile
Discovered by
Customer
Published by the vendor
Published
Jun 16, 2026
Assigned by palo_alto

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user.

Weakness: CWE-79

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • PowerSchool · Employee Access Center

Credit

Menachem (Momo) Rothbart