Modify the image upload form for custom item image

  • Posts: 20
  • Thank you received: 0
11 years 4 months ago #108220

Hi,
I am soooooooooo happy with Hikashop. Best product ever. Support team is brilliant and intuitive.

I have messed around with various extensions to upload images, but since my images are needed for my products, I've come back to Hikashop and am happy to be using custom item image fields in my cart.

While I was experimenting, I learned that clients can upload php files disguised as png images and unfortunately I too can do this with the custom item image, although I don't have the skill to create something really viscous or destructive.

I get that the images extensions are limited by the configuration settings, but I would like to add checks to the upload form. Where is it?

Thanks in advance.

Please Log in or Create an account to join the conversation.

  • Posts: 82759
  • Thank you received: 13346
  • MODERATOR
11 years 4 months ago #108231

Hi,

There is no need for such check. if the customer renames a php file with the extension of an image, the system will indeed allow the upload of the file, but the file will be treated as an image, not as a php file and thus no hack will be possible as the PHP code won't be executed by your web server.

There is no trigger on the file saving process so you won't have to add custom code in a view of the checkout to load the image in memory and check it yourself if you want but there is no need for that as I explained in my first paragraph.

The following user(s) said Thank You: LenaK

Please Log in or Create an account to join the conversation.

  • Posts: 20
  • Thank you received: 0
11 years 4 months ago #108234

i must be getting somewhere because i understand. Thank you. :P

Please Log in or Create an account to join the conversation.

Time to create page: 0.054 seconds
Powered by Kunena Forum