We have received a report about potential hole in the script that is prone to cross site scripting vulnerability.
It is very unlikely that an administration script could be used by hackers because only site administrators have access to it but we decided to not take the risk and protect our users even from the slightest chance of attack and released a patch for this problem.
We would recommend to download the fixed script from here:
Further, extract the above mentioned file into the 'admin' folder of your shop replacing an existing one. Don't forget to make a backup copy of the current file in case something goes wrong.