I'm a pentester, you generally don't fix the issues you find so much as provide guidance and references on how it might be done. The defenders/app developers are in a much better position to fix most issues, they generally either weren't aware of that class of vulnerability or unaware of a specific method of exploiting the issue. Most web devs, if you tell them you found an XSS, would know what you meant and basic prevention, but maybe not the specific way you exploited it. But I don't go tweak their whitelist or implement better output encoding for them.
That said, you do have to know the defensive side well, even if you don't implement it yourself.