<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Gravity Support Forums Topic: Image Upload Validation</title>
		<link>https://legacy.forums.gravityhelp.com/topic/image-upload-validation</link>
		<description>Gravity Support Forums Topic: Image Upload Validation</description>
		<language>en-US</language>
		<pubDate>Sun, 19 Apr 2026 23:14:10 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.1</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>https://legacy.forums.gravityhelp.com/search.php</link>
		</textInput>
		<atom:link href="https://legacy.forums.gravityhelp.com/rss/topic/image-upload-validation" rel="self" type="application/rss+xml" />

		<item>
			<title>Chris Hajer on "Image Upload Validation"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/image-upload-validation#post-72558</link>
			<pubDate>Sat, 25 Aug 2012 08:37:32 +0000</pubDate>
			<dc:creator>Chris Hajer</dc:creator>
			<guid isPermaLink="false">72558@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;You're not missing any configuration options.  Most users don't misname their files intentionally.  A malicious user could try to get around upload restrictions by giving a PHP file an image extension, and uploading that, but then what happens?&#60;/p&#62;
&#60;p&#62;We have discussed this in the past:&#60;br /&#62;
&#60;a href=&#34;http://www.gravityhelp.com/forums/topic/file-upload-security-1&#34; rel=&#34;nofollow&#34;&#62;http://www.gravityhelp.com/forums/topic/file-upload-security-1&#60;/a&#62;
&#60;/p&#62;</description>
		</item>
		<item>
			<title>ezoehunt on "Image Upload Validation"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/image-upload-validation#post-71054</link>
			<pubDate>Tue, 14 Aug 2012 15:54:24 +0000</pubDate>
			<dc:creator>ezoehunt</dc:creator>
			<guid isPermaLink="false">71054@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;It is possible to upload a file to the Image field that does not match filetype gif, jpg, or png. For instance, I just uploaded a php file with .gif extension through the Image field. Isn't this problematic? Can you add a filetype check to the image upload field?&#60;/p&#62;
&#60;p&#62;Also able to upload a php file with .pdf extension to the File field. &#60;/p&#62;
&#60;p&#62;These don't seem to be checking mime type. Do you expect users to manage that on their own? Or is there something I'm missing in my Gravity Forms configuration?
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
