Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.opera.com/docs/changelogs/unified/1210/ | |
http://www.opera.com/support/kb/view/1030/ | vendor advisory |