app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24070.json"