For reference: the issue is linked from the security advisory page at https://www.freeplane.org/wiki/index.php/Fixed_security_vulnerabilities . Ahtough there is unfortunately no reference to the fixing commit (which wuould have been good for downstreams to help), we know the versions fixed are 1.5.20 and 1.6.1_17.
That might help identifying the required fix. HTH, Regards, Salvatore