Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Access Center 23.10 (CVE-2026-12425) | HOL Guard CVE