Before this reaches a level rehashing the old "sell it on the blackmarket", I would like to clarify an issue here.
The policy change that occurred for Sean (the person the OP is using for his argument) was that Uber had clarified a change, without any clear notification. I blame the HackerOne Platform here, there is no way to send a notice of scope unless the program owner manually appends it at the top (in the case of yahoo https://hackerone.com/yahoo)
So its scope (https://hackerone.com/uber) changed from in scope
"Exposed Administrative Panels and Ports (Excluding OneLogin)"
to
"Exposed Administrative Panels that don't require login credentials"
With ports moved to out of scope unless,
"Open ports without an accompanying proof-of-concept demonstrating vulnerability"
I cannot speak for the OP and the validity of his XSS bug however.