In certain screens, the Profile "Description" field was not properly escaped to prevent cross site scripting.
CiviCRM version 5.28.0 and earlier
CiviCRM version 5.28.1 and 5.27.5 ESR
Upgrade to the latest version of CiviCRM
Ben Hubbard of Armadillo Security for reporting the issue
Seamus Lee of CiviCRM Core Team for fixing the issue
security/core#96