Index: lams_central/src/java/org/lamsfoundation/lams/web/tag/MultiLinesOutputTag.java =================================================================== RCS file: /usr/local/cvsroot/lams_central/src/java/org/lamsfoundation/lams/web/tag/MultiLinesOutputTag.java,v diff -u -r1.4.14.2 -r1.4.14.3 --- lams_central/src/java/org/lamsfoundation/lams/web/tag/MultiLinesOutputTag.java 5 May 2016 08:09:44 -0000 1.4.14.2 +++ lams_central/src/java/org/lamsfoundation/lams/web/tag/MultiLinesOutputTag.java 1 Sep 2016 05:59:32 -0000 1.4.14.3 @@ -5,7 +5,7 @@ import javax.servlet.jsp.JspException; import javax.servlet.jsp.tagext.SimpleTagSupport; -import org.apache.commons.lang.StringEscapeUtils; +import org.springframework.web.util.HtmlUtils; /** * JSP tag. It converts text from \n or \r\n to <BR> before rendering. @@ -24,7 +24,7 @@ @Override public void doTag() throws JspException, IOException { if (escapeHtml) { - value = StringEscapeUtils.escapeHtml(value); + value = HtmlUtils.htmlEscape(value); } value = value.replaceAll("\n", "
"); getJspContext().getOut().write(value.toString());