Suggestions needed
I submit a valid P3 report. They agree that it is P3, but due to program policy, they are not accepting it. So, he asked me to chain this vulnerability to a P2 or P1 and closed my report as N/A.
After a lot of time, I finally escalated this to P2 and posted the entire chained report in the comments.
My real question is: since my original report is in a closed state, should I submit a new report, open an RAR, or leave the P2 chained report in the comments and wait a few days?