diff --git a/odoo/addons/base/tests/test_mail.py b/odoo/addons/base/tests/test_mail.py
index 5693906c092..297a32cf67e 100644
--- a/odoo/addons/base/tests/test_mail.py
+++ b/odoo/addons/base/tests/test_mail.py
@@ -281,6 +281,11 @@ class TestSanitizer(unittest.TestCase):
self.assertNotIn('
404 - Not Found', html)
self.assertIn('404 - Not Found
', html)
+ def test_cid_with_at(self):
+ img_tag = '
'
+ sanitized = html_sanitize(img_tag, sanitize_tags=False, strip_classes=True)
+ self.assertEqual(img_tag, sanitized, "img with can have cid containing @ and shouldn't be escaped")
+
# ms office is currently not supported, have to find a way to support it
# def test_30_email_msoffice(self):
# new_html = html_sanitize(test_mail_examples.MSOFFICE_1, remove=True)
diff --git a/odoo/tools/mail.py b/odoo/tools/mail.py
index 668d0678f88..6992c206009 100644
--- a/odoo/tools/mail.py
+++ b/odoo/tools/mail.py
@@ -180,7 +180,7 @@ def html_sanitize(src, silent=True, sanitize_tags=True, sanitize_attributes=Fals
part = re.compile(r"(<(([^a<>]|a[^<>\s])[^<>]*)@[^<>]+>)", re.IGNORECASE | re.DOTALL)
# remove results containing cite="mid:email_like@address" (ex: blockquote cite)
# cite_except = re.compile(r"^((?!cite[\s]*=['\"]).)*$", re.IGNORECASE)
- src = part.sub(lambda m: (u'cite=' not in m.group(1) and u'alt=' not in m.group(1)) and misc.html_escape(m.group(1)) or m.group(1), src)
+ src = part.sub(lambda m: (u'cite=' not in m.group(1) and u'alt=' not in m.group(1) and u'src=' not in m.group(1)) and misc.html_escape(m.group(1)) or m.group(1), src)
# html encode mako tags <% ... %> to decode them later and keep them alive, otherwise they are stripped by the cleaner
src = src.replace(u'<%', misc.html_escape(u'<%'))
src = src.replace(u'%>', misc.html_escape(u'%>'))