Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user.
Problem types
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Product status
23.10
Credits
Menachem (Momo) Rothbart
References
github.com/...lob/main/2026/PANW-2026-0002/PANW-2026-0002.md