The advanced data entry form reacts weirdly if you enter HTML. Specifically, if you enter
<script>alert(1)</script> or the like, the code in the script tag will be executed.
The real reason this is bad is that the existence of one XSS-type issue implies that there may be others lurking. That’s a scary thought—but despite that, this particular bug is so small as to barely be worth fixing. That said, it’s probably worth taking a good look at anywhere else this type of issue may crop up, and ensuring that there isn’t anywhere where an actual XSS is possible.