If I'm not mistaking, he discovered the vulnerability while developing an app for its university, then he sent it to the system administrators.
His troubles began when he checked later if the security hole was still opened.
His troubles began when he checked later if the security hole was still opened.
It seems like he had no malicious intent (At least I believe him) but his school and the vendor basically went nuclear on him.