Opera contains a flaw that is triggered when parsing Cross-Origin Resource Sharing (CORS) requests when a preflight request was omitted. With a specially crafted request, a remote attacker can more easily conduct a cross-site request forgery (CSRF) attack.