[Fixed in CME v1.0.2019.0630] CMC XML files storing Windows Password in clear text?
Posted: Sat Jun 29, 2019 10:11 pm
Paul,
I upgraded to the new CMC v2.2 and had great success importing my TV series metadata from MyMovies. I had a couple of series that I needed to update the MyMovies profiles, and in troubleshooting that issue, I discovered my Windows credentials are being written to the new CMC XML files titled mmTitle.xlm. It happens near the end of the file under the DunePaths location for both movies and TV series.
Do I have something misconfigured in MyMovies or CMC or is this working as intended? It seems to be a huge security risk storing my Windows password in plain text throughout the hard drive and in hundreds of folders. See below for an example of what I am seeing near the end of all XML files created my CMC. I removed my actual password from the example and replaced it with "PASSWORD" below.
Brian Scholl
SAMPLE mmTitle.xml
<WatchedEvents>
<WatchedEvent Name="" Date="3/9/2012 12:00:00 AM" Before="False" State="-1" Session="" How="" Notes=""/>
</WatchedEvents>
<DataChanged>11/23/2014 4:53:35 PM</DataChanged>
<DiscLocations>
<Disc Name="Disc 1" TypeA="1" LocationA="smb://HTPC/Blu-Ray3/Apollo 13"/>
</DiscLocations>
<Locations/>
<DunePaths>
<![CDATA[Disc 1##BluRay##smb://Brian Scholl:PASSWORD@HTPC/Blu-Ray3/Apollo 13/APOLLO_13_GLO_G51.iso]]>
</DunePaths>
</PersonalData>
</Title>
I upgraded to the new CMC v2.2 and had great success importing my TV series metadata from MyMovies. I had a couple of series that I needed to update the MyMovies profiles, and in troubleshooting that issue, I discovered my Windows credentials are being written to the new CMC XML files titled mmTitle.xlm. It happens near the end of the file under the DunePaths location for both movies and TV series.
Do I have something misconfigured in MyMovies or CMC or is this working as intended? It seems to be a huge security risk storing my Windows password in plain text throughout the hard drive and in hundreds of folders. See below for an example of what I am seeing near the end of all XML files created my CMC. I removed my actual password from the example and replaced it with "PASSWORD" below.
Brian Scholl
SAMPLE mmTitle.xml
<WatchedEvents>
<WatchedEvent Name="" Date="3/9/2012 12:00:00 AM" Before="False" State="-1" Session="" How="" Notes=""/>
</WatchedEvents>
<DataChanged>11/23/2014 4:53:35 PM</DataChanged>
<DiscLocations>
<Disc Name="Disc 1" TypeA="1" LocationA="smb://HTPC/Blu-Ray3/Apollo 13"/>
</DiscLocations>
<Locations/>
<DunePaths>
<![CDATA[Disc 1##BluRay##smb://Brian Scholl:PASSWORD@HTPC/Blu-Ray3/Apollo 13/APOLLO_13_GLO_G51.iso]]>
</DunePaths>
</PersonalData>
</Title>