: If you discover a vulnerability in a third-party site, report it through official bug bounty programs or contact the organization directly.

SQLi impossible: user input is data, not code.