Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-28 11:15
Updated : 2026-01-29 16:31
NVD link : CVE-2025-41351
Mitre link : CVE-2025-41351
CVE.ORG link : CVE-2025-41351
JSON object : View
Products Affected
No product.
CWE
CWE-649
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking
