As Aaron mentioned, the default settings don't grant "admin" groups UserManagement commands which would grant them perms to change levels for users.
Another way would be through RCON. If they have the RCON password for the server, they'd be able to access high-level commands without actually being a high-level rank.
I don't know much about the exploits since I don't pay attention to that, but I haven't had any problems yet. But then again, I choose my staff very carefully.