<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Gravity Support Forums Topic: Export download not working / security issue</title>
		<link>https://legacy.forums.gravityhelp.com/topic/export-download-not-working-security-issue</link>
		<description>Gravity Support Forums Topic: Export download not working / security issue</description>
		<language>en-US</language>
		<pubDate>Mon, 20 Apr 2026 08:27:29 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.1</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>https://legacy.forums.gravityhelp.com/search.php</link>
		</textInput>
		<atom:link href="https://legacy.forums.gravityhelp.com/rss/topic/export-download-not-working-security-issue" rel="self" type="application/rss+xml" />

		<item>
			<title>Carl Hancock on "Export download not working / security issue"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/export-download-not-working-security-issue#post-22531</link>
			<pubDate>Tue, 05 Apr 2011 11:52:25 +0000</pubDate>
			<dc:creator>Carl Hancock</dc:creator>
			<guid isPermaLink="false">22531@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Yes, it's been resolved.  1.3.12.2 is pretty old actually.  There have been a few major releases since then, with 1.5 being the latest.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>stickyeyes on "Export download not working / security issue"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/export-download-not-working-security-issue#post-22529</link>
			<pubDate>Tue, 05 Apr 2011 11:50:14 +0000</pubDate>
			<dc:creator>stickyeyes</dc:creator>
			<guid isPermaLink="false">22529@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Hi Carl,&#60;/p&#62;
&#60;p&#62;We are using version 1.3.12.2. We haven't had our subscription that long but I am aware you are now at 1.5. Do you know if this is an issue that has been resolved in the latest version?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Carl Hancock on "Export download not working / security issue"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/export-download-not-working-security-issue#post-22519</link>
			<pubDate>Tue, 05 Apr 2011 11:33:10 +0000</pubDate>
			<dc:creator>Carl Hancock</dc:creator>
			<guid isPermaLink="false">22519@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;You didn't say which version of Gravity Forms you are using.  The export functionality has been rewritten in later versions and revised again in Gravity Forms v1.5.  In later versions, a file isn't created.  It's streamed directly to the browser and functions exactly like the WordPress Export feature for exporting posts.  It was written the same way.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>stickyeyes on "Export download not working / security issue"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/export-download-not-working-security-issue#post-22506</link>
			<pubDate>Tue, 05 Apr 2011 10:55:28 +0000</pubDate>
			<dc:creator>stickyeyes</dc:creator>
			<guid isPermaLink="false">22506@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Just to add: I am unable to find a changelog for the latest version of gravity forms, can anyone can confirm if this issue has already been dealt with?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>stickyeyes on "Export download not working / security issue"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/export-download-not-working-security-issue#post-22504</link>
			<pubDate>Tue, 05 Apr 2011 10:50:55 +0000</pubDate>
			<dc:creator>stickyeyes</dc:creator>
			<guid isPermaLink="false">22504@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Hello,&#60;/p&#62;
&#60;p&#62;We have been using Gravity Forms on a number of high profile Wordpress installations and discovered a serious security issue with the 'export' feature. It seems that the download feature does not work. I have tested it in the latest version of Firefox (4.0) and Google Chrome (12.0.712.0 Dev Build) and it simply does not download (or even alerts the user of what has happened). Instead, it generates a file (perhaps temporarily) in a folder within the uploads directory. I assume that this is for streaming to the browser (when really it should be done on-the-fly using PHP headers instead of creating a hard-copy of the file). &#60;/p&#62;
&#60;p&#62;As a result of the above, the user-sensitive data now becomes publicly accessible as the uploads directory requires 755 permissions as stated on Wordpress Documentation. To combat this issue, a permissions change (using .htaccess for example) to block access is required.&#60;/p&#62;
&#60;p&#62;Can someone please advise on whether this is an issue you guys are aware of and if not, investigate, as it is and has been (for us) a serious security flaw.&#60;/p&#62;
&#60;p&#62;P.S, The export did work in Safari.
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
