30 Minutes later I was in my professor's account. Their birthday month and day were public on Facebook, so it was only a matter of guessing their age.
I reported this to our IT department and they were not pleased. They let me know they had the power to expel me but wouldn't.
A week later, I found another exploit. I think blackboard group chat allowed JS execution outright. I redirected the class to "disney.com" but never disclosed it to IT because of the earlier threats.