Long story short, after submitting, we went back and forth and BugCrowd refused to acknowledge that this was an actual vulnerability and did not pay out, despite me not even submitting the bug in hopes for a payout. I just wanted Invision's users to be safer online while using their service.
How do we - as a technology community, or even furthermore, developer community - deal with situations like this?
Note: I am disclosing this publicly as it has now nearly been one year since my original submission, and the bug remains.