Solution : https://service.sap.com/sap/support/notes/834929 (SAP Service marketplace login required)
Key words :
e-recruiting bsp applications, cross site scripting, content->forceencode = 'enabled', undesired side effects, <%=controller->ps_template-description%>, sap e-recruiting 2, bsp extension hrrcf_bsp_ext, bsp bsp-application, relevant support package, bsp extensions -> hrrcf_bsp_ext
Related Notes :
1061439 | Cross Site Scripting (XSS), encoding user entries |