Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-48231.json"