https://www.vice.com/en_us/article/59nzjz/teen-security-rese...
This article has more details about the reasons Demirkapi was suspended. Apparently he first tried to contact Follett (the software maker) directly, but they ignored him. He then tried to use the software itself to send a message Follett, but the message was instead broadcast to a large number of parents, teachers, and administrators across the district. This does seem pretty irresponsible, and Demirkapi said he understood the reason for his suspension.
Thus, this doesn't seem like the usual "person reports vulnerability and is punished for it" story.
Of course the ultimate responsibility lies with the software makers who have these vulnerabilities in their software and who don't respond when someone reports them.