diff --git a/core/htmlsanitizer.class.inc.php b/core/htmlsanitizer.class.inc.php index 34a1747dc..907e94286 100644 --- a/core/htmlsanitizer.class.inc.php +++ b/core/htmlsanitizer.class.inc.php @@ -79,10 +79,13 @@ abstract class HTMLSanitizer /** * Dummy HTMLSanitizer which does nothing at all! + * * Can be used if HTML Sanitization is not important * (for example when importing "safe" data during an on-boarding) * and performance is at stake * + * **Warning** : this won't filter HTML inserted in iTop at all, so this is a great security issue ! + * Also, the InlineImage objects processing won't be called. */ class HTMLNullSanitizer extends HTMLSanitizer { diff --git a/core/inlineimage.class.inc.php b/core/inlineimage.class.inc.php index 73baf46a5..c34dc163f 100644 --- a/core/inlineimage.class.inc.php +++ b/core/inlineimage.class.inc.php @@ -479,7 +479,7 @@ EOF $sAppRootUrl = utils::GetAbsoluteUrlAppRoot(); return -<<