Hello guys!
I have a small problem. I would like to allow my customers to enter embed code for Youtube so that their videos can be seen on their blogs, but the XSS cleaning replaces the <> with other code (as it should do).
What I am asking is the following:
1. Is there a major security issue if I remove the Embed and Object from the Input Library?
(Which successfully allows the embed code to be used).
2. Is there another way to allow input of Youtube embed code?
Thankful for all help!
Kind Regards,
Daniel
