report/security/report security check preventexecpath: Difference between revisions
From MoodleDocs
Dan Marsden (talk | contribs) (add some info about preventexecpath) |
(No difference)
|
Revision as of 06:50, 11 September 2017
Moodle administrators are able to define the path to a number of executable files hosted Some administration options allow setting the path to executable files on the web server such as du, aspell, ghostscript and others. This can potentially cause a security risk. You can prevent adminstrators from changing these paths by adding the following setting to your config.php file:
$CFG->preventexecpath = true;
You should also explicitly set the relevant paths in your config.php file such as: $CFG->pathtodu $CFG->pathtounoconv $CFG->aspellpath