CVE-2013-1639

Opera Browser < 12.12 - CSRF

Title source: rule

Description

Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that triggers a CORS request.

Scores

EPSS 0.0011
EPSS Percentile 28.9%

Classification

CWE
CWE-352
Status draft

Affected Products (8)

opera/opera_browser < 12.12
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser
opera/opera_browser

Timeline

Published Feb 08, 2013
Tracked Since Feb 18, 2026