Interesting to see this come up. About 2 years ago I found a similar exploit in blackboard (XSS that could lead to session hijacking) and found that there was absolutely no way to report the vulnerability except through their help-and-support chat.
After reporting it, they thanked me and said they would be in touch when they addressed it. I never heard from them again, and it seems they didn't take security much more seriously.