@iframe0x01 I got N/A for same kind of report on @hackerone platform, there is one private program where i reported it and H1 team got me N/A . when I showed your report he/she just changed status as informative :D
@Random_Robbie There was two url:
https://t.co/zOU8f2uPPN
With login form.
But flower interface was available without username and password.
https://t.co/YbVfKi4oHC
I have set XSS payload in my username field, after support opened my ticket booom Blind XSS payload fired, thanks (https://t.co/sS5Z1sHJyt) for such a great project :)