Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user. | |
| Title | Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Access Center 23.10 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2026-06-16T18:37:57.288Z
Reserved: 2026-06-16T17:02:05.062Z
Link: CVE-2026-12425
No data.
Status : Awaiting Analysis
Published: 2026-06-16T20:16:28.443
Modified: 2026-06-16T20:42:25.013
Link: CVE-2026-12425
No data.
OpenCVE Enrichment
No data.