A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Profile Albums plugin for MyBB is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the albums.php script using the album parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.