Problem: Under certain conditions, your site can be attacked XSS. Attacker can steal cookies; browser if administrator use outdated browser. So he can access to authorized area. View more about XSS : http://en.wikipedia.org/wiki/Cross-site_scripting
Affected version:7.x - 8.5
The degree of danger:Low
Download the patch and copy to your own server patch:dle7_85_path.zip