Generally boils down to whether or not the company has some kind of bug bounty program. If they do and it’s in scope, you will probably get paid...in this case likely $1-5k.
Smaller companies that don’t have a bug bounty might provide a token reward just because, larger companies generally won’t.
Any company that hasn’t explicitly authorized ‘research’ might also choose to sue.
Smaller companies that don’t have a bug bounty might provide a token reward just because, larger companies generally won’t.
Any company that hasn’t explicitly authorized ‘research’ might also choose to sue.