Difference between revisions of "report/security/report security check embed"

Jump to: navigation, search

Note: You are currently viewing documentation for Moodle 3.3. Up-to-date documentation for the latest stable version of Moodle is probably available here: report/security/report security check embed.

(stub template, see also forum link, category)
 
(explanation)
 
(2 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{stub}}
+
{{Security overview report}}Allowing ordinary users to embed Flash and other media in their texts (e.g. forum posts) can be a problem because those rich media objects can be used to steal admin or teacher access, even if the media object is on another server.
 +
 
 +
Thus it is recommended that the setting 'Allow EMBED and OBJECT tags' in 'Site policies' is left unticked.
  
 
==See also==
 
==See also==
  
 
* Using Moodle [http://moodle.org/mod/forum/view.php?id=7301 Security and Privacy forum]
 
* Using Moodle [http://moodle.org/mod/forum/view.php?id=7301 Security and Privacy forum]
 
[[Category:Security]]
 

Latest revision as of 07:29, 28 November 2016

Allowing ordinary users to embed Flash and other media in their texts (e.g. forum posts) can be a problem because those rich media objects can be used to steal admin or teacher access, even if the media object is on another server.

Thus it is recommended that the setting 'Allow EMBED and OBJECT tags' in 'Site policies' is left unticked.

See also