report/security/report security check embed

Jump to: navigation, search

Note: You are currently viewing documentation for Moodle 3.1. Up-to-date documentation for the latest stable version of Moodle is probably available here: report/security/report security check embed.

Allowing ordinary users to embed Flash and other media in their texts (eg forum posts) can be a problem because those rich media objects can be used to steal admin or teacher access, even if the media object is on another server.

Thus it is recommended that the setting 'Allow EMBED and OBJECT tags' in 'Site policies' is left unticked.

See also