SQL injection in a checkout flow
I found an unauthenticated SQL injection in the promo-code validation of a public membership checkout. Testing showed it could be used to bypass payment. I reported the issue through the operator's official channel and coordinated the disclosure with them.