<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Gravity Support Forums Topic: Payment amount spoofed somehow</title>
		<link>https://legacy.forums.gravityhelp.com/topic/payment-amount-spoofed-somehow</link>
		<description>Gravity Support Forums Topic: Payment amount spoofed somehow</description>
		<language>en-US</language>
		<pubDate>Mon, 20 Apr 2026 16:54:16 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.1</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>https://legacy.forums.gravityhelp.com/search.php</link>
		</textInput>
		<atom:link href="https://legacy.forums.gravityhelp.com/rss/topic/payment-amount-spoofed-somehow" rel="self" type="application/rss+xml" />

		<item>
			<title>Carl Hancock on "Payment amount spoofed somehow"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/payment-amount-spoofed-somehow#post-52970</link>
			<pubDate>Tue, 20 Mar 2012 12:22:22 +0000</pubDate>
			<dc:creator>Carl Hancock</dc:creator>
			<guid isPermaLink="false">52970@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;It is not possible to spoof the prices that appears on the form and have those prices submitted and stored as such.&#60;/p&#62;
&#60;p&#62;It IS possible to manipulate the javascript that displays the pricing and the Total price on the form itself.  HOWEVER, the form processor doesn't rely on this javascript for the pricing and it calculates the total using server side code when the form is submitted.&#60;/p&#62;
&#60;p&#62;When Gravity Forms processes the PayPal IPN request, it verifies that the PayPal IPN request totals match the totals stored in the form entry data.  It will reject the IPN request if they do not match.&#60;/p&#62;
&#60;p&#62;So yes, there is verification in place to prevent users from manipulating pricing data both on the form, and when checking out via PayPal.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>James on "Payment amount spoofed somehow"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/payment-amount-spoofed-somehow#post-52829</link>
			<pubDate>Mon, 19 Mar 2012 08:00:51 +0000</pubDate>
			<dc:creator>James</dc:creator>
			<guid isPermaLink="false">52829@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Does anyone have an update on this?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>James on "Payment amount spoofed somehow"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/payment-amount-spoofed-somehow#post-52654</link>
			<pubDate>Fri, 16 Mar 2012 06:32:13 +0000</pubDate>
			<dc:creator>James</dc:creator>
			<guid isPermaLink="false">52654@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Hello,&#60;/p&#62;
&#60;p&#62;Yesterday someone somehow purchased a product off my site that should have cost $3 for $0.01. After doing a bit of research online some people are saying it's possible to spoof posted variables and do this.&#60;/p&#62;
&#60;p&#62;The bigger problem is that the Gravity forms entry actually shows the wrong amount, but the purchase still completed! As I'm using the user addon as well to work as a digital delivery system this basically means someone got this product for free.&#60;/p&#62;
&#60;p&#62;Does Gravity forms check that the amount returned from Paypal matches the product value? If it doesn't is there anyway I can implement this?&#60;/p&#62;
&#60;p&#62;Thanks,&#60;br /&#62;
James
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
