diff --git a/core/modules/field_ui/src/Form/FieldConfigEditForm.php b/core/modules/field_ui/src/Form/FieldConfigEditForm.php index ba972a9..7ea912c 100644 --- a/core/modules/field_ui/src/Form/FieldConfigEditForm.php +++ b/core/modules/field_ui/src/Form/FieldConfigEditForm.php @@ -65,7 +65,7 @@ public function form(array $form, FormStateInterface $form_state) { '#title' => $this->t('Help text'), '#default_value' => $this->entity->getDescription(), '#rows' => 5, - '#description' => $this->t('Instructions to present to the user below this field on the editing form.
Allowed HTML tags: @tags', array('@tags' => FieldFilteredString::displayAllowedTags())) . '
' . $this->t('This field supports tokens.'), + '#description' => $this->t('Instructions to present to the user below this field on the editing form.
Allowed HTML tags: @tags
This field supports tokens.', array('@tags' => FieldFilteredString::displayAllowedTags())), '#weight' => -10, ); diff --git a/core/modules/system/system.admin.inc b/core/modules/system/system.admin.inc index 11b72a5..9ff8fe9 100644 --- a/core/modules/system/system.admin.inc +++ b/core/modules/system/system.admin.inc @@ -261,7 +261,9 @@ function theme_system_modules_details($variables) { '#type' => 'details', '#title' => $title, '#attributes' => array('id' => $module['enable']['#id'] . '-description'), - '#description' => $description, + // #description is built up using lots of markup therefore we need to + // XSS admin filter it instead of auto-escape. + '#description' => ['#markup' => $description], ); $row[] = ['class' => ['description', 'expand'], 'data' => $details];