Here is the issue - a vulnerability I reported earlier to WHMCS details a SQL injection on the clientside, if you inject that you are able to access the database, from there you can just modify things in the backend and/or read settings from the database, therefore you don't need...