"Hi team,
I found a vulnerability in your website and want to disclose it to you.
Let me know if you have any active bug bounty program or is there any compensation for reporting vulnerabilities?"
What's the correct course of action for a software team, or management, when a user asks to disclose a vulnerability they've found?