diff --git a/core/modules/field_ui/src/Form/FieldConfigEditForm.php b/core/modules/field_ui/src/Form/FieldConfigEditForm.php
index ba972a9..7ea912c 100644
--- a/core/modules/field_ui/src/Form/FieldConfigEditForm.php
+++ b/core/modules/field_ui/src/Form/FieldConfigEditForm.php
@@ -65,7 +65,7 @@ public function form(array $form, FormStateInterface $form_state) {
'#title' => $this->t('Help text'),
'#default_value' => $this->entity->getDescription(),
'#rows' => 5,
- '#description' => $this->t('Instructions to present to the user below this field on the editing form.
Allowed HTML tags: @tags', array('@tags' => FieldFilteredString::displayAllowedTags())) . '
' . $this->t('This field supports tokens.'),
+ '#description' => $this->t('Instructions to present to the user below this field on the editing form.
Allowed HTML tags: @tags
This field supports tokens.', array('@tags' => FieldFilteredString::displayAllowedTags())),
'#weight' => -10,
);
diff --git a/core/modules/system/system.admin.inc b/core/modules/system/system.admin.inc
index 11b72a5..9ff8fe9 100644
--- a/core/modules/system/system.admin.inc
+++ b/core/modules/system/system.admin.inc
@@ -261,7 +261,9 @@ function theme_system_modules_details($variables) {
'#type' => 'details',
'#title' => $title,
'#attributes' => array('id' => $module['enable']['#id'] . '-description'),
- '#description' => $description,
+ // #description is built up using lots of markup therefore we need to
+ // XSS admin filter it instead of auto-escape.
+ '#description' => ['#markup' => $description],
);
$row[] = ['class' => ['description', 'expand'], 'data' => $details];