{"id":"CVE-2026-12425","title":"Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is po…","summary":"Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is po…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"powerschool","product":"employee_access_center","affected":["employee_access_center = 23.10"],"published":"2026-06-16","updated":"2026-09-30","sourceUpdated":"2026-09-30T20:17:32.243","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12425","references":[{"url":"https://github.com/PaloAltoNetworks/u42-vulnerability-disclosures/blob/main/2026/PANW-2026-0002/PANW-2026-0003.md","label":"psirt@paloaltonetworks.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-17T15:04:50.510597Z"},"scores":{"nvd":6.1,"cna":5.7},"epss":0.00149,"epssPercentile":0.03465,"ingestedAt":"2026-09-30T20:23:19.465Z","slug":"CVE-2026-12425","body":"## Overview\n\nImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user.\n\n## Affected\n\n- `employee_access_center = 23.10`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}