It has been discovered that TYPO3 Core is vulnerable to Arbitrary Code Execution, Path Traversal, Cross-Site Scripting (XSS), SQL injection and Information Disclosure.
Please read this advisory for a description and solutions of all the above mentioned issues: