You're way out of line flagging this, in my opinion. It's a security issue, and a big one at that. I also see no reason to believe that the user is attempting to "score points". Lastly, the comment is in fact quite useful.
I agree wholeheartedly with this. We're supposed to be the good guys--revealing security issues should be something that gets heavily rewarded with karma.