6.8
CVSSv2

CVE-2013-1639

Published: 08/02/2013 Updated: 08/03/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Opera prior to 12.13 does not send CORS preflight requests in all required cases, which allows remote malicious users to bypass a CSRF protection mechanism via a crafted web site that triggers a CORS request.

Vulnerable Product Search on Vulmon Subscribe to Product

opera opera browser 12.10

opera opera browser 12.01

opera opera browser 12.02

opera opera browser 12.11

opera opera browser 12.00

opera opera browser