Launchpad.net

CVE 2014-3800

XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.

See the CVE page on Mitre.org for more details.