If a vulnerability is discovered on a website, is it better to contact the business owner or site designer/owner? [closed]

There are plenty of questions on this site about how to report a vulnerability (such as SQLi or XSS,) but none of them really answer my question of who to.
I understand for a big corporation (although not all,) such as a government website… Continue reading If a vulnerability is discovered on a website, is it better to contact the business owner or site designer/owner? [closed]

I have access to companies internal files through SSRF and Path traversal both but want to leverage it further to website takeover

I have access to companies internal files through SSRF and Path traversal both but want to leverage it further to website takeover. Thus I can increase the impact and get more bounty then what they will pay now.
I have access to files like… Continue reading I have access to companies internal files through SSRF and Path traversal both but want to leverage it further to website takeover