I want to say this might be offtopic but I will appreciate your contribution. I detected a security bug on a popular POS software which enables me to login to the software without password. And it gives me full access to the software which ordinarily should not be and I should be limited to the department of the company I work for but now I can view, edit, create anything. Also logged in successfully in another company using same software. I'm thinking of reporting it to the software manufacturer but with compensation cos it's an highly sensitive issue with ability to run down any company using the software.