Commerce Custom Order Status provides forms for administrators to add, edit, and delete order statuses from the order settings screen.
The module doesn't sufficiently sanitize the output of the status names.
This vulnerability is mitigated by the fact that an attacker must have a role with the "configure order settings" permission.
Install the latest version:
- If you use the Commerce Custom Order Status module for Drupal 7.x, upgrade to Commerce Custom Order Status 7.x-1.1
Also see the Commerce Custom Order Status project page.
- Greg Knaddison of the Drupal Security Team