@Muntrive@Hacker0x01 I had a similar case that took me a month, three disclosed reports, and even a research paper just to explain what OAuth and one-click ATO are—only for it to be triaged as Low. Before that, they even insisted I self-close the report to avoid damaging my reputation.
Result:
payload from attacker origin executes on https://t.co/IX1scAV6ka.
can be used to bypass WAFs more conveniently since there is no malicious payload in the URL.