We can basically dump the entire database if we want to.
Then, we can identify the site administrators (this can also be easily done by simply exploring the site and seeing who writes the admin messages), get their user codes from the DB, and send them as a cookie to the website, using, e.g., Burp Suite.
This will allow us to log in as administrators, and do whatever we want with the site.