This might be a fairly major issue.
My user can change their settings if they know the path to the admin page!
If the user enters the URL to edit a user they can change their own permissions and gain full control!
http://www.mysite_url_here.com/admindirectory/admin_control.php?adminID=2
The user is allowed to access this page, and allowed to change settings on this page. They can open up the site and do quite a bit of harm.
They cannot access the page without the variable in the url, but they have full access otherwise. If someone has installed Zen, or used Zen, they will have an understanding of the expected path and will probably monkey around. I did. They can even lock the main admin out by simply appending the URL with adminID=1! Try it.
Is there a setting that can be changed to fix this?
One other thing. Is there any way to restrict what they see on their 'Admin Home' page? I would prefer that they didn't see all stats.