TL;DR funny descope of the week
In April I logged a blind, stored XSS that landed in an admin panel, and exfilled 27Mb of aggregated data, along with live promo codes etc.
The report was logged as a high impact, and went through platform triage without issue, but the programme immediately downgraded to a medium, without any explanation.
So, I added a polite comment, explaining that all the platform taxonomies suggest a high for stored XSS, and asking them to review and reconsider.
Which they did, by downgrading the report to a low. lolz.
<-- insert slow-clap here -->