CVE-2014-3800: Xbmc

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.

Affected products

  • Xbmc Xbmc: version 13.0 only

Published 2014-08-07. Last modified 2026-06-17.