Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-24019 PoC — Fortinet FortiClientEms 代码问题漏洞

Source
Associated Vulnerability
Title:Fortinet FortiClientEms 代码问题漏洞 (CVE-2021-24019)
Description:An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)
Description
Exploit
Readme
# CVE-2021-24019
Exploit
FortiClient EMS 6.2.6 - Authentication Bypass Exploit

Overview

This script automates session token validation to test if authentication can be bypassed in FortiClient EMS 6.2.6. The user provides the target, and the script checks a list of session tokens for valid access.


---

Usage Instructions

1. Update tokens.txt with session tokens. Example:

csrftoken=example123...
sessionid=abcdef123...


2. Run the script:

python exploit.py


3. Enter the target URL when prompted.


4. If a valid token is found, access is granted.



---

Legal Disclaimer

This script is for educational purposes only. Unauthorized testing on systems without explicit permission is illegal. 
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →