This issue was reported to Dropbox and promptly fixed over 3 weeks ago. We appreciate the contributions of this researcher and everyone who helps keep Dropbox safe.
(I work for Dropbox but don't speak for it in this capacity)
It is not generally the case that companies disclose quickly-patched vulnerabilities that were reported by white-hat security researchers. Example of a similar vulnerability with a similar response time by another company: https://blog.duosecurity.com/2013/02/bypassing-googles-two-f...
Researchers disclose a while after the vulnerability is patched. This is standard practice.