Data and content security
Content can potentially contain malicious elements. It further needs to be protected from unauthorized access. In this section, we shall deal with the security of data and content.
Content created within Moodle
Users are able to create content in Moodle by either using the resource editor or uploading files. A number of settings are available to partly prevent the misuse of these.
HTML allows the embedding of code that uses the explicit <EMBED>
and <OBJECT>
tags. This mechanism has recently gained popularity with sites, such as YouTube, Prezi, Voki, and Google Maps, providing code to be embedded for their users. Potentially, malicious code can be put in the embedded script, which is why its support is deactivated by default. To activate it, go to Security | Site policies and locate the Allow EMBED and OBJECT tags parameter:
Moodle's editors automatically remove any unwanted HTML elements and attributes via a so-called HTML purifier. Moodle supports a more...