Details
-
Bug
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
2.0.0-alpha
-
None
Description
the version of JSTL escapeXML function in facelets currently only escapes '<', but not '>'. Since '>' can be interpreted as XML markup, and to be consistent with the JSP JSTL implementation, it should be escaped as well.