Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.07
EPSS Ranking 91.2%