There are a collection of files within Zoho CRM that COULD contain potentially sensitive commercial parameters and logic in them, and that can be accessed without authentication.
This includes the CRM Data Model, Custom Picklist values, Custom Role / Profile names and any business settings or logic embedded in Zoho Hosted Widgets or Client Scripts.
Now... whilst these URLs are not publicly available in the first instance, anyone with legitimate access to the CRM (an employee, contractor or consultant) or access to a Client Portal version of the CRM (a member of the sales team with restricted access or a customer) can easily discover them, make a note of them and then access or share them further down the line without needing to log into the CRM.
We disclosed this finding to Zoho.
Zoho's response:
Based on the investigation, the exposed files contain only organization-specific metadata, such as module names, field definitions, API names, relationships, and picklist values.
They do not expose customer records, credentials, authentication tokens, or provide a way to compromise the CRM organization.
Therefore, no direct security impact is demonstrated. The exposure is limited to metadata and does not allow unauthorized access to CRM data or functionality.
We are therefore closing this report as Informative.
In our experience, businesses tend to use Picklists as efficient shortcuts to ensure consistency, and will often include values such as key user names, hierarchcal roles, brands names, competitor names, product descriptors and parameters, locations etc.
Whilst there is no direct security impact (in Zoho's assessment), there could inadvertantly be Personally Identifible Information (PII) and at the very least acts as a blueprint of internal business logic.
Also, because a Client Script or Widget is Zoho-hosted, there could be the misconception that it is somehow more secure than an externally hosted Widget or Script - and therefore could be coded with exposed business logic and other sensitive parameters.
Client Scripts and code associated with a Zoho-hosted widgets (HTML, CSS, Javascript) are not secured behind any authentication method.
Thoughts?
Does having your Data Model, Module Names, Field Names, Custom Picklist Values, Client Scripts and Widget code available via unauthenticated URLs concern you?